CRLF Injection Vulnerability in IBM Maximo Asset Management and SmartCloud Control Desk
CVE-2012-3333

Currently unrated

Key Information:

Vendor
IBM
Vendor
CVE Published:
26 May 2014

Summary

The vulnerability in IBM Maximo Asset Management and SmartCloud Control Desk allows remote attackers to exploit CRLF injection, impacting the integrity of HTTP headers. This can lead to unauthorized actions, such as HTTP response splitting, via crafted URL parameters. Effective mitigations include applying recommended patches and maintaining secure coding practices.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.