CVE-2009-0120

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
15/01/2009
Last modified:
09/04/2025

Description

The IBM WebSphere DataPower XML Security Gateway XS40 with firmware 3.6.1.5 allows remote attackers to cause a denial of service (device reboot) by sending data over an established SSL connection, as demonstrated by the abc\r\n\r\n string data.

Vulnerable products and versions

CPE From Up to
cpe:2.3:h:ibm:websphere_datapower_xml_security_gateway_xs40:3.6.1.5:*:*:*:*:*:*:*