CVE-2013-0494: Medium severity ibm b2b sterling integrator vulnerability
Published Aug 9, 2013
·Updated
IBM Sterling B2B Integrator 5.0 and 5.1 allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted HTTP (1) Range or (2) Request-Range header.
Affected Software
2 affected components
IBM Sterling B2B Integrator=5.0
IBM Sterling B2B Integrator=5.1
Event History
Aug 9, 2013
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-0494?
CVE-2013-0494 is classified as a denial of service vulnerability.
2
How do I fix CVE-2013-0494?
To mitigate CVE-2013-0494, it is recommended to upgrade IBM Sterling B2B Integrator to version 5.2 or later.
3
Who is affected by CVE-2013-0494?
CVE-2013-0494 affects users of IBM Sterling B2B Integrator versions 5.0 and 5.1.
4
What can attackers do exploiting CVE-2013-0494?
Exploiting CVE-2013-0494 allows remote attackers to cause significant memory and CPU consumption, leading to denial of service.
5
Is there a workaround for CVE-2013-0494?
There is no official workaround for CVE-2013-0494; the best solution is to upgrade to a secure version.