MaxDB WebTools 7.5.00.18 and earlier allows remote attackers to cause a denial of service (application crash) via an HTTP GET request for a file that does not exist, followed by two carriage returns, which causes a NULL dereference.
Link | Tags |
---|---|
http://marc.info/?l=bugtraq&m=110244542000340&w=2 | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/18387 | vdb entry |