HTTP Response Splitting Vulnerability in IBM BigFix Platform
CVE-2018-1474

6.1MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
12 December 2018

What is CVE-2018-1474?

The IBM BigFix Platform versions 9.2.0 through 9.2.14 and 9.5 through 9.5.9 are susceptible to HTTP response splitting due to inadequate validation of user-generated input. An attacker can exploit this flaw to inject arbitrary HTTP headers, leading to the potential of the server returning a split HTTP response. This could enable the attacker to conduct additional malicious actions, including web cache poisoning and cross-site scripting, which could compromise sensitive data. Recommended actions include patching affected versions or enhancing user input validation methods to mitigate the risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

BigFix Platform 9.5.9

BigFix Platform 9.2.0

BigFix Platform 9.2.14

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.