Host Header Injection Vulnerability in IBM Tivoli Monitoring Products
CVE-2016-5933
4.6MEDIUM
Summary
IBM Tivoli Monitoring versions 6.2 and 6.3 are vulnerable to a host header injection attack that can enable malicious actors to exploit HTTP requests. This vulnerability may lead to HTTP cache poisoning, allowing an attacker to manipulate cached responses or bypass firewall protections, thereby compromising the security of the affected systems. It is essential for users to apply necessary patches or mitigations to safeguard against these risks.
Affected Version(s)
Tivoli Monitoring V6 6.2.0
Tivoli Monitoring V6 6.2.1
Tivoli Monitoring V6 6.2.2
References
CVSS V3.1
Score:
4.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved