PT-2014-5062 · Ibm · Ibm Websphere Application Server+1
Published
2014-08-12
·
Updated
2017-08-29
·
CVE-2014-3069
CVSS v2.0
3.5
Low
| Vector | AV:N/AC:M/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Curam Social Program Management (SPM) version 6.0.5.5
Description
The issue affects the Universal Access component in IBM Curam Social Program Management, allowing remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks. This is possible when WebSphere Application Server is not used.
Recommendations
For IBM Curam Social Program Management version 6.0.5.5, consider restricting access to the Universal Access component until a fix is available, and ensure WebSphere Application Server is utilized to mitigate the risk of CRLF injection vulnerabilities.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ibm Curam Social Program Management
Ibm Websphere Application Server