CVE-2014-0859IBM Websphere Application Server vulnerability

4 documents4 sources
Severity
5.0MEDIUMNVD
EPSS
1.6%
top 18.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 1
Latest updateMay 17

Description

The web-server plugin in IBM WebSphere Application Server (WAS) 7.x before 7.0.0.33, 8.x before 8.0.0.9, and 8.5.x before 8.5.5.2, when POST retries are enabled, allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-vgwp-x4rp-775q: The web-server plugin in IBM WebSphere Application Server (WAS) 72022-05-17
CVEList
CVE-2014-0859: The web-server plugin in IBM WebSphere Application Server (WAS) 72014-05-01

💬Community

1
Bugzilla
CVE-2014-0174 cumin: session cookies lack httponly setting2014-04-09
CVE-2014-0859 — IBM vulnerability | cvebase