CVE-2012-2190: IBM WebSphere Application Server
Medium severity, CVSS 5.0. EPSS: 2.4% chance of exploitation in the next 30 days.
IBM Global Security Kit (aka GSKit), as used in IBM HTTP Server in IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.45, 7.0.x before 7.0.0.25, 8.0.x before 8.0.0.4, and 8.5.x before 8.5.0.1, allows remote attackers to cause a denial of service (daemon crash) via a crafted ClientHello message in the TLS Handshake Protocol.
Affected products
- IBM WebSphere Application Server: version 6.1.0 only; version 6.1.0.0 only; version 6.1.0.1 only; version 6.1.0.2 only; version 6.1.0.3 only; version 6.1.0.5 only; …
Published 2012-08-21. Last modified 2026-06-16.