PQ91084 - Possible Denial of Service within Caching Proxy
Downloadable files
Abstract
Possible Denial of Service (DoS) within Caching Proxy with incomplete GET requests when JunctionRewrite and UseCookie directives are active.
Download Description
PQ91084 resolves the following problem.
PROBLEM:
This APAR is for Caching Proxy Versions 5.0.0.2 through 5.0.2.20, released with IBM® WebSphere® Application Server Version 5.0 with IBM WebSphere Edge Server Fix Pack 2, and all releases of IBM WebSphere Application Server Version 5.0.1 and 5.0.2 products. The Caching Proxy component fails to handle incomplete GET requests when the JunctionRewrite and UseCookie directives are active. Successful exploitation of this exposure can cause a Denial of Service condition.
LOCAL FIX:
Any valid HTTP request, which must include a URL, optional HTTP version and other HTTP headers, will not trigger this vulnerability. If you are using the JunctionRewrite plug-in with directive JunctionRewrite On, the vulnerability will not be triggered.
Instead of the UseCookie option for JunctionRewrite directive, use the Junction plug-in, by setting the JunctionRewrite On directive and the 2 JunctionRewrite plug-in entries to avoid this Denial of Service condition.
This APAR fix resolves the vulnerability in the junction rewrite module. After applying the fix, an error page will be returned when an attempt to exploit this vulnerability is made, and the connection between the client and the proxy will be closed.
Prerequisites
None
Installation Instructions
Please refer to the updates file for 5.0. This is applicable for both versions 5.0 and 5.1.
IBM, the IBM logo and ibm.com are trademarks of International Business Machines Corp., registered in many jurisdictions worldwide. Other product and service names might be trademarks of IBM or other companies. A current list of IBM trademarks is available on the Web at "Copyright and trademark information" at www.ibm.com/legal/copytrade.shtml.
Rate this page
Please take a moment to complete this form to help us better serve you.