RULE(RULE ID:332844)

Rule General Information
Release Date: 2021-03-26
Rule Name: IBM WebSphere Application Server Buffer Overflow Vulnerability (CVE-2005-1872)
Severity:
CVE ID:
Rule Protection Details
Description: There exists a buffer overflow vulnerability in IBM's WebSphere Application Server. The vulnerability is caused by improper validation of user-supplied input in the application authentication process. A successful attack can terminate the server process. It is also possible to inject and execute arbitrary code on the target. In a simple attack case aimed at creating a denial of service condition, the affected service will terminate. All established connections are reset. All web applications hosted by the target are unavailable until the application server is restarted. In a more sophisticated attack scenario, where the malicious user is successful in injecting and executing code, the behaviour of the system is dependent on the nature the injected code. Any code injected into the vulnerable component would execute in the security context of the service process.
Impact: A buffer overflow vulnerability can be triggered by an attacker in the context of the vulnerable product. Further attacks includes arbitrary code execution and denial of service.
Affected OS: Windows, Linux, Others
Reference: http://marc.info/?l=bugtraq&m=111817727120752&w=2
http://www-1.ibm.com/support/docview.wss?rs=180&uid=swg24009775
http://www.appsecinc.com/resources/alerts/general/WEBSPHERE-001.html
Solutions
Please contact the software vendor to update the software patch.