First published: Mon Aug 08 2016(Updated: )
IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.0.x before 8.0.0.13, 8.5.0.x before 8.5.5.10, 8.5.0.x and 16.0.0.x Liberty before Liberty Fix Pack 16.0.0.3, and 9.0.0.x before 9.0.0.1 allows remote attackers to cause a denial of service via crafted SIP messages.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Application Server Feature Pack for Web Services | =7.0 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.0 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.1 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.2 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.3 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.4 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.5 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.6 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.7 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.8 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.9 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.10 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.11 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.12 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.13 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.14 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.15 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.16 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.17 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.18 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.19 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.21 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.22 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.23 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.24 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.25 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.27 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.28 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.29 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.31 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.32 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.33 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.34 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.35 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.36 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.37 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.38 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.39 | |
IBM WebSphere Application Server Feature Pack for Web Services | =7.0.0.41 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.0 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.1 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.2 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.3 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.4 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.5 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.6 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.7 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.8 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.9 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.10 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.11 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.0.0.12 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.5.0.0 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.5.0.0 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.5.0.1 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.5.0.2 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.5.5.0 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.5.5.1 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.5.5.2 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.5.5.4 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.5.5.5 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.5.5.6 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.5.5.7 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.5.5.8 | |
IBM WebSphere Application Server Feature Pack for Web Services | =8.5.5.9 | |
IBM WebSphere Application Server Feature Pack for Web Services | =9.0.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-2960 has a severity rating that typically categorizes it as a denial of service vulnerability.
To fix CVE-2016-2960, you should upgrade to IBM WebSphere Application Server versions 7.0.0.43, 8.0.0.13, 8.5.5.10, or later.
CVE-2016-2960 affects various versions of IBM WebSphere Application Server, including versions 7.x, 8.x, 8.5.x, and 16.0.x.
Attackers can exploit CVE-2016-2960 to send crafted SIP messages that lead to a denial of service.
Yes, a patch is available in the form of upgrades to the specified versions of IBM WebSphere Application Server.