PT-2014-5062 · Ibm · Ibm Websphere Application Server+1

Published

2014-08-12

·

Updated

2017-08-29

·

CVE-2014-3069

CVSS v2.0

3.5

Low

VectorAV:N/AC:M/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions IBM Curam Social Program Management (SPM) version 6.0.5.5
Description The issue affects the Universal Access component in IBM Curam Social Program Management, allowing remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks. This is possible when WebSphere Application Server is not used.
Recommendations For IBM Curam Social Program Management version 6.0.5.5, consider restricting access to the Universal Access component until a fix is available, and ensure WebSphere Application Server is utilized to mitigate the risk of CRLF injection vulnerabilities.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2014-3069

Affected Products

Ibm Curam Social Program Management
Ibm Websphere Application Server