PT-2017-6364 · Ibm · Ibm Flex System En6131 40Gb Ethernet+1

Publicado

2017-08-25

·

Atualizado

2017-08-30

·

CVE-2014-9564

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions IBM Flex System EN6131 40Gb Ethernet and IB6131 40Gb Infiniband Switch firmware versions prior to 3.4.1110
Description The issue allows remote attackers to inject arbitrary HTTP headers, which can lead to HTTP response splitting attacks. This can result in web cache poisoning or cross-site scripting (XSS) attacks, or allow attackers to obtain sensitive information via multiple unspecified parameters.
Recommendations For versions prior to 3.4.1110, update the firmware to version 3.4.1110 or later to resolve the issue. As a temporary workaround, consider restricting access to the HTTP endpoints to minimize the risk of exploitation. Avoid using unspecified parameters in the affected HTTP requests until the issue is resolved.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-9564

Produtos afetados

Ib6131 40Gb Infiniband Switch
Ibm Flex System En6131 40Gb Ethernet