CRLF Injection Vulnerability in IBM Curam Social Program Management Software
CVE-2014-4803

Currently unrated

Key Information:

Vendor
IBM
Vendor
CVE Published:
13 February 2015

Summary

A CRLF injection vulnerability exists in the Universal Access implementation of IBM Curam Social Program Management. When users operate the software without the WebSphere Application Server, authenticated attackers can exploit this vulnerability to inject arbitrary HTTP headers. This can lead to HTTP response splitting attacks, which may disrupt the user experience or be leveraged for additional malicious actions. Users are urged to update to the latest versions to mitigate potential risks.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.