CVE-2014-0859: Medium severity IBM WebSphere Application Server Feature Pack for Web Services vulnerability
The web-server plugin in IBM WebSphere Application Server (WAS) 7.x before 7.0.0.33, 8.x before 8.0.0.9, and 8.5.x before 8.5.5.2, when POST retries are enabled, allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM WebSphere Application Server (WAS) web-server pluginto a version that resolves this vulnerability.Fixed in 7.0.0.33 - Upgrade
Upgrade
IBM WebSphere Application Server (WAS) web-server pluginto a version that resolves this vulnerability.Fixed in 8.0.0.9 - Upgrade
Upgrade
IBM WebSphere Application Server (WAS) web-server pluginto a version that resolves this vulnerability.Fixed in 8.5.5.2
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0859?
CVE-2014-0859 is classified as a denial of service vulnerability within IBM WebSphere Application Server.
How do I fix CVE-2014-0859?
To fix CVE-2014-0859, you should upgrade IBM WebSphere Application Server to versions 7.0.0.33, 8.0.0.9, or 8.5.5.2 or later.
What versions of IBM WebSphere Application Server are affected by CVE-2014-0859?
CVE-2014-0859 affects IBM WebSphere Application Server versions 7.x before 7.0.0.33, 8.x before 8.0.0.9, and 8.5.x before 8.5.5.2.
Can CVE-2014-0859 be exploited remotely?
Yes, CVE-2014-0859 can be exploited remotely due to the nature of the denial of service vulnerability.
What causes the vulnerability in CVE-2014-0859?
The vulnerability in CVE-2014-0859 is caused by the web-server plugin when POST retries are enabled.