IBM WebSphere Application Server 4.0.1 through 4.0.3 allows remote attackers to cause a denial of service (application crash) via an HTTP request with a large header.
https://exchange.xforce.ibmcloud.com/vulnerabilities/25619
http://www.vupen.com/english/advisories/2006/1214