PT-2015-5554 · Ibm · Ibm Websphere Extreme Scale

Published

2015-10-04

·

Updated

2015-10-05

·

CVE-2015-2028

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions IBM WebSphere eXtreme Scale versions 7.1.0 through 7.1.0.2 IBM WebSphere eXtreme Scale versions 7.1.1 through 7.1.1.0
Description The issue allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL. This is due to a CRLF injection vulnerability.
Recommendations For IBM WebSphere eXtreme Scale versions 7.1.0 through 7.1.0.2, update to version 7.1.0.3 or later. For IBM WebSphere eXtreme Scale versions 7.1.1 through 7.1.1.0, update to version 7.1.1.1 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2015-2028

Affected Products

Ibm Websphere Extreme Scale