CVE-2008-4678
IBM WebSphere Application Server 6.0.2 - Denial of Service via Long HTTP Host Header
Title source: llmDescription
The HTTP_Request_Parser method in the HTTP Transport component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.31 allows remote attackers to cause a denial of service (controller 0C4 abend and application hang) via a long HTTP Host header, related to "storage overlay" on the stack and a "parse failure."
References (6)
Core 6
Core References
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2008/2871
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg27006876
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/32296
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/31839
Various Sources vendor-advisory
x_refsource_aixapar
http://www-1.ibm.com/support/docview.wss?uid=swg1PK69371
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/45993
Scores
EPSS
0.0192
EPSS Percentile
77.7%
Details
CWE
CWE-399
Status
published
Products (16)
ibm/websphere_application_server
6.0.2
ibm/websphere_application_server
6.0.2.1
ibm/websphere_application_server
6.0.2.2
ibm/websphere_application_server
6.0.2.3
ibm/websphere_application_server
6.0.2.4
ibm/websphere_application_server
6.0.2.5
ibm/websphere_application_server
6.0.2.6
ibm/websphere_application_server
6.0.2.9
ibm/websphere_application_server
6.0.2.11
ibm/websphere_application_server
6.0.2.13
... and 6 more
Published
Oct 22, 2008
Tracked Since
Feb 18, 2026