IBM SecureWay Firewall before 4.2.2 performs extra processing before determining that a packet is invalid and dropping it, which allows remote attackers to cause a denial of service (resource exhaustion) via a flood of malformed TCP packets without any flags set.
| Software | From | Fixed in |
|---|---|---|
| ibm / secureway_firewall | 4.2 | 4.2.x |
| ibm / secureway_firewall | 4.2.1 | 4.2.1.x |