CVE-2011-1315

IBM WebSphere Application Server < 7.0.0.15 - Denial of Service via JMS Receive Call

Title source: llm
STIX 2.1

Description

Memory leak in the messaging engine in IBM WebSphere Application Server (WAS) before 7.0.0.15 allows remote attackers to cause a denial of service (memory consumption) via network connections associated with a NULL return value from a synchronous JMS receive call.

References (2)

Core 2
Core References
Various Sources vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1PM23626
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg27014463

Scores

EPSS 0.0111
EPSS Percentile 62.4%

Details

CWE
CWE-399
Status published
Products (50)
ibm/websphere_application_server 2.0
ibm/websphere_application_server 3.0
ibm/websphere_application_server 3.0.2
ibm/websphere_application_server 3.0.2.1
ibm/websphere_application_server 3.0.2.2
ibm/websphere_application_server 3.0.2.3
ibm/websphere_application_server 3.0.2.4
ibm/websphere_application_server 3.0.21
ibm/websphere_application_server 3.5
ibm/websphere_application_server 3.5.1
... and 40 more
Published Mar 08, 2011
Tracked Since Feb 18, 2026