CVE-2010-1612

IBM WebSphere DataPower XML Accelerator XA35 < 3.8.0.0 - Denial of Service via Malformed ICMP Packets

Title source: llm
STIX 2.1

Description

The IBM WebSphere DataPower XML Accelerator XA35, Low Latency Appliance XM70, Integration Appliance XI50, B2B Appliance XB60, and XML Security Gateway XS40 SOA Appliances before 3.8.0.0, when a QLOGIC Ethernet interface is used, allow remote attackers to cause a denial of service (interface outage) via malformed ICMP packets to the 0.0.0.0 destination IP address.

References (8)

Core 8
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/509163/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/37952
Patch, Vendor Advisory vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1IC61364

Scores

EPSS 0.0175
EPSS Percentile 75.5%

Details

Status published
Products (50)
ibm/websphere_datapower_b2b_appliance_xb60 3.7.3.1
ibm/websphere_datapower_b2b_appliance_xb60 3.7.3.2
ibm/websphere_datapower_b2b_appliance_xb60 3.7.3.3
ibm/websphere_datapower_b2b_appliance_xb60 3.7.3.4
ibm/websphere_datapower_b2b_appliance_xb60 3.7.3.5
ibm/websphere_datapower_b2b_appliance_xb60 3.7.3.6
ibm/websphere_datapower_b2b_appliance_xb60 3.7.3.7
ibm/websphere_datapower_b2b_appliance_xb60 3.7.3.8
ibm/websphere_datapower_b2b_appliance_xb60 3.7.3.9
ibm/websphere_datapower_b2b_appliance_xb60 3.8.0.0
... and 40 more
Published Apr 29, 2010
Tracked Since Feb 18, 2026