CVE-2011-1322
IBM WebSphere Application Server 6.1.0.x < 6.1.0.37 and 7.x < 7.0.0.15 - Denial of Service via Encrypted SOAP Messages
Title source: llmDescription
The SOAP with Attachments API for Java (SAAJ) implementation in the Web Services component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.37 and 7.x before 7.0.0.15 allows remote attackers to cause a denial of service (memory consumption) via encrypted SOAP messages.
References (2)
Core 2
Core References
Vendor Advisory vendor-advisory
x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1PM19534
Various Sources x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg27014463
Scores
EPSS
0.0163
EPSS Percentile
73.8%
Details
CWE
CWE-399
Status
published
Products (33)
ibm/websphere_application_server
6.1.0
ibm/websphere_application_server
6.1.0.0
ibm/websphere_application_server
6.1.0.1
ibm/websphere_application_server
6.1.0.2
ibm/websphere_application_server
6.1.0.3
ibm/websphere_application_server
6.1.0.5
ibm/websphere_application_server
6.1.0.7
ibm/websphere_application_server
6.1.0.9
ibm/websphere_application_server
6.1.0.11
ibm/websphere_application_server
6.1.0.12
... and 23 more
Published
Mar 08, 2011
Tracked Since
Feb 18, 2026