PT-2019-16957 · Ibm · Ibm Jazz For Service Management

·

CVE-2019-4186

·

Published

2019-09-05

·

Updated

2022-12-09

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions IBM Jazz for Service Management version 1.1.3
Description The issue is caused by incorrect trust in the HTTP Host header during caching, allowing a remote attacker to inject arbitrary HTTP headers by sending a specially crafted HTTP GET request. This could enable various attacks, including cross-site scripting, cache poisoning, or session hijacking.
Recommendations For IBM Jazz for Service Management version 1.1.3, update to a version that fixes the HTTP header injection issue.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-4186

Affected Products

Ibm Jazz For Service Management