PT-2024-4958 · Ibm · Ibm Datacap Navigator
Published
2024-07-12
·
Updated
2024-07-16
·
CVE-2024-39736
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
IBM Datacap Navigator versions 9.1.5 through 9.1.9
Description:
The issue is related to improper validation of input by the HOST headers in HTTP requests, which could allow a remote attacker to conduct various attacks, including cross-site scripting, cache poisoning, or session hijacking.
Recommendations:
For versions 9.1.5 through 9.1.9, update to a version that properly validates input by the HOST headers to prevent HTTP header injection attacks.
As a temporary workaround, consider restricting access to the vulnerable system to minimize the risk of exploitation.
Fix
Improper Encoding or Escaping of Output
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ibm Datacap Navigator