Header Spoofing Vulnerability in IBM Event Streams
CVE-2018-1833

5.3MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
18 December 2018

Summary

A vulnerability found in IBM Event Streams 2018.3.0 allows a remote attacker with authorized CLI access to submit API requests with a falsified Host request header. This exploitation enables the attacker to manipulate the header, potentially leading to unauthorized actions within the application. This issue highlights the critical importance of validating inputs and headers in API requests to prevent malicious activities.

Affected Version(s)

Event Streams 2018.3.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.