CVE-2014-4764: High severity ibm websphere application server feature pack for web services vulnerability
Published Aug 22, 2014
·Updated
IBM WebSphere Application Server (WAS) 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.3, when Load Balancer for IPv4 Dispatcher is enabled, allows remote attackers to cause a denial of service (Load Balancer crash) via unspecified vectors.
Affected Software
16 affected components
IBM WebSphere Application Server Feature Pack for Web Services=8.5.0.0
IBM WebSphere Application Server Feature Pack for Web Services=8.5.0.1
IBM WebSphere Application Server Feature Pack for Web Services=8.5.0.2
IBM WebSphere Application Server Feature Pack for Web Services=8.5.5.0
IBM WebSphere Application Server Feature Pack for Web Services=8.5.5.1
IBM WebSphere Application Server Feature Pack for Web Services=8.5.5.2
IBM WebSphere Application Server Feature Pack for Web Services=8.0.0.0
IBM WebSphere Application Server Feature Pack for Web Services=8.0.0.1
IBM WebSphere Application Server Feature Pack for Web Services=8.0.0.2
IBM WebSphere Application Server Feature Pack for Web Services=8.0.0.3
IBM WebSphere Application Server Feature Pack for Web Services=8.0.0.4
IBM WebSphere Application Server Feature Pack for Web Services=8.0.0.5
IBM WebSphere Application Server Feature Pack for Web Services=8.0.0.6
IBM WebSphere Application Server Feature Pack for Web Services=8.0.0.7
IBM WebSphere Application Server Feature Pack for Web Services=8.0.0.8
IBM WebSphere Application Server Feature Pack for Web Services=8.0.0.9
Event History
Aug 22, 2014
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-4764?
CVE-2014-4764 is categorized as a denial of service vulnerability.
2
How do I fix CVE-2014-4764?
To fix CVE-2014-4764, you should upgrade to IBM WebSphere Application Server versions 8.0.0.10 or 8.5.5.3 or later.
3
What software is affected by CVE-2014-4764?
CVE-2014-4764 affects IBM WebSphere Application Server versions 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.3.
4
What type of attack can exploit CVE-2014-4764?
CVE-2014-4764 can be exploited by remote attackers to cause a denial of service that results in the Load Balancer crashing.
5
When was CVE-2014-4764 disclosed?
CVE-2014-4764 was disclosed in 2014.