CVE-2008-4678

IBM WebSphere Application Server 6.0.2 - Denial of Service via Long HTTP Host Header

Title source: llm
STIX 2.1

Description

The HTTP_Request_Parser method in the HTTP Transport component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.31 allows remote attackers to cause a denial of service (controller 0C4 abend and application hang) via a long HTTP Host header, related to "storage overlay" on the stack and a "parse failure."

References (6)

Core 6
Core References
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/2871
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg27006876
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32296
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/31839
Various Sources vendor-advisory x_refsource_aixapar
http://www-1.ibm.com/support/docview.wss?uid=swg1PK69371
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/45993

Scores

EPSS 0.0192
EPSS Percentile 77.7%

Details

CWE
CWE-399
Status published
Products (16)
ibm/websphere_application_server 6.0.2
ibm/websphere_application_server 6.0.2.1
ibm/websphere_application_server 6.0.2.2
ibm/websphere_application_server 6.0.2.3
ibm/websphere_application_server 6.0.2.4
ibm/websphere_application_server 6.0.2.5
ibm/websphere_application_server 6.0.2.6
ibm/websphere_application_server 6.0.2.9
ibm/websphere_application_server 6.0.2.11
ibm/websphere_application_server 6.0.2.13
... and 6 more
Published Oct 22, 2008
Tracked Since Feb 18, 2026