Host Header Injection Vulnerability in IBM SmartCloud Analytics
CVE-2019-4216
4.6MEDIUM
Summary
IBM SmartCloud Analytics versions 1.3.1 to 1.3.5 are susceptible to a host header injection vulnerability. This flaw could allow attackers to exploit manipulation of the Host HTTP header, potentially leading to significant security issues such as HTTP cache poisoning or unauthorized access to the firewall. Organizations utilizing affected versions should evaluate their systems and apply appropriate security patches to mitigate risks. For more details, refer to IBM's security advisory.
Affected Version(s)
SmartCloud Analytics 1.3.1
SmartCloud Analytics 1.3.2
SmartCloud Analytics 1.3.3
References
CVSS V3.1
Score:
4.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved