CRLF Injection Vulnerability in IBM WebSphere eXtreme Scale
CVE-2016-0400

6.1MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
2 July 2016

Summary

The CRLF injection vulnerability in IBM WebSphere eXtreme Scale allows remote attackers to inject malicious HTTP headers and conduct HTTP response splitting attacks. This can occur through carefully crafted URLs that exploit vulnerabilities in specific versions of the software, potentially leading to unauthorized access and data leakage.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.