PT-2014-5062 · Ibm · Ibm Websphere Application Server+1
Publicado
2014-08-12
·
Atualizado
2017-08-29
·
CVE-2014-3069
CVSS v2.0
3.5
Baixa
| Vetor | AV:N/AC:M/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Curam Social Program Management (SPM) version 6.0.5.5
Description
The issue affects the Universal Access component in IBM Curam Social Program Management, allowing remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks. This is possible when WebSphere Application Server is not used.
Recommendations
For IBM Curam Social Program Management version 6.0.5.5, consider restricting access to the Universal Access component until a fix is available, and ensure WebSphere Application Server is utilized to mitigate the risk of CRLF injection vulnerabilities.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Ibm Curam Social Program Management
Ibm Websphere Application Server