CRLF Injection Vulnerability in IBM WebSphere Commerce
CVE-2015-0196
Currently unrated
Summary
The CRLF injection vulnerability in IBM WebSphere Commerce allows remote attackers to manipulate HTTP headers by injecting crafted URLs. This can lead to HTTP response splitting attacks, which can compromise sensitive data and even redirect users to malicious sites. Companies using vulnerable versions of this product should implement mitigations and upgrade to secure versions to prevent exploitation.
References
Timeline
Vulnerability published
Vulnerability Reserved