CRLF Injection Vulnerability in IBM WebSphere Commerce
CVE-2015-0196

Currently unrated

Key Information:

Vendor
IBM
Vendor
CVE Published:
29 June 2015

Summary

The CRLF injection vulnerability in IBM WebSphere Commerce allows remote attackers to manipulate HTTP headers by injecting crafted URLs. This can lead to HTTP response splitting attacks, which can compromise sensitive data and even redirect users to malicious sites. Companies using vulnerable versions of this product should implement mitigations and upgrade to secure versions to prevent exploitation.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.