CVE
- Id
- 3995
- CVE No.
- CVE-2001-1191
- Status
- Candidate
- Description
- WebSeal in IBM Tivoli SecureWay Policy Director 3.8 allows remote attackers to cause a denial of service (crash) via a URL that ends in %2e.
- Phase
- Proposed (20020315)
- Votes
- ACCEPT(1) Green | MODIFY(1) Frech | NOOP(5) Christey, Cole, Foat, Wall, Ziese
- Comments
- Frech> XF:tivoli-webseal-dos(7716) | http://online.securityfocus.com/archive/1/268124 | Christey> BUGTRAQ:20020417 IBM Security Advisory: IBM Tivoli Policy Director WebSEAL | URL:http://archives.neohapsis.com/archives/bugtraq/2002-04/0223.html | | The vendor says that "there is no denial of service | vulnerability" but goes on to describe "a defect related to | the use of SSL junctions between the WebSEAL component and Web | Servers. This defect can cause the WebSEAL component to fail if SSL | junctions are being used, and certain URLs are then passed across | these junctions." This still sounds like a DoS to me, albeit | one that might not appear in all configurations. | | Fix capitalization: "WebSEAL"