CVE

Id
3995  
CVE No.
CVE-2001-1191  
Status
Candidate  
Description
WebSeal in IBM Tivoli SecureWay Policy Director 3.8 allows remote attackers to cause a denial of service (crash) via a URL that ends in %2e.  
Phase
Proposed (20020315)  
Votes
ACCEPT(1) Green | MODIFY(1) Frech | NOOP(5) Christey, Cole, Foat, Wall, Ziese  
Comments
Frech> XF:tivoli-webseal-dos(7716) | http://online.securityfocus.com/archive/1/268124 | Christey> BUGTRAQ:20020417 IBM Security Advisory: IBM Tivoli Policy Director WebSEAL | URL:http://archives.neohapsis.com/archives/bugtraq/2002-04/0223.html | | The vendor says that "there is no denial of service | vulnerability" but goes on to describe "a defect related to | the use of SSL junctions between the WebSEAL component and Web | Servers. This defect can cause the WebSEAL component to fail if SSL | junctions are being used, and certain URLs are then passed across | these junctions." This still sounds like a DoS to me, albeit | one that might not appear in all configurations. | | Fix capitalization: "WebSEAL"