First published: Fri Aug 09 2013(Updated: )
IBM Sterling B2B Integrator 5.0 and 5.1 allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted HTTP (1) Range or (2) Request-Range header.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM B2B Sterling Integrator | =5.0 | |
IBM B2B Sterling Integrator | =5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-0494 is classified as a denial of service vulnerability.
To mitigate CVE-2013-0494, it is recommended to upgrade IBM Sterling B2B Integrator to version 5.2 or later.
CVE-2013-0494 affects users of IBM Sterling B2B Integrator versions 5.0 and 5.1.
Exploiting CVE-2013-0494 allows remote attackers to cause significant memory and CPU consumption, leading to denial of service.
There is no official workaround for CVE-2013-0494; the best solution is to upgrade to a secure version.