IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to cause a denial of service by directly calling the macro.d2w macro with a long string of %0a characters.
| Software | From | Fixed in |
|---|---|---|
| ibm / net.commerce_hosting_server | 3.1.1 | 3.1.1.x |
| ibm / net.commerce | 3.1 | 3.1.x |
| ibm / net.commerce | 2.0 | 2.0.x |
| ibm / net.commerce | 3.0 | 3.0.x |
| ibm / net.commerce | 3.1.2 | 3.1.2.x |
| ibm / net.commerce_hosting_server | 3.1.2 | 3.1.2.x |
| ibm / websphere_application_server | 5.1.0.3 | 5.1.0.3.x |
| ibm / net.commerce | 3.1.1 | 3.1.1.x |