VYPR
Unrated severityNVD Advisory· Published Oct 22, 2008· Updated Jun 16, 2026

CVE-2008-4678

CVE-2008-4678

Description

The HTTP_Request_Parser method in the HTTP Transport component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.31 allows remote attackers to cause a denial of service (controller 0C4 abend and application hang) via a long HTTP Host header, related to "storage overlay" on the stack and a "parse failure."

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

18
  • cpe:2.3:a:ibm:websphere_application_server:6.0.2:*:*:*:*:*:*:*+ 16 more
    • cpe:2.3:a:ibm:websphere_application_server:6.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:websphere_application_server:6.0.2.1:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:websphere_application_server:6.0.2.11:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:websphere_application_server:6.0.2.13:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:websphere_application_server:6.0.2.15:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:websphere_application_server:6.0.2.17:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:websphere_application_server:6.0.2.19:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:websphere_application_server:6.0.2.2:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:websphere_application_server:6.0.2.23:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:websphere_application_server:6.0.2.25:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:websphere_application_server:6.0.2.27:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:websphere_application_server:6.0.2.3:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:websphere_application_server:6.0.2.4:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:websphere_application_server:6.0.2.5:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:websphere_application_server:6.0.2.6:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:websphere_application_server:6.0.2.9:*:*:*:*:*:*:*
    • (no CPE)range: <6.0.2.31
  • IBM/WASllm-fuzzy
    Range: <6.0.2.31

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.