Host Header Injection Vulnerability in IBM SmartCloud Analytics
CVE-2019-4216

4.6MEDIUM

Key Information:

Vendor

IBM

Vendor
CVE Published:
22 November 2019

What is CVE-2019-4216?

IBM SmartCloud Analytics versions 1.3.1 to 1.3.5 are susceptible to a host header injection vulnerability. This flaw could allow attackers to exploit manipulation of the Host HTTP header, potentially leading to significant security issues such as HTTP cache poisoning or unauthorized access to the firewall. Organizations utilizing affected versions should evaluate their systems and apply appropriate security patches to mitigate risks. For more details, refer to IBM's security advisory.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

SmartCloud Analytics 1.3.1

SmartCloud Analytics 1.3.2

SmartCloud Analytics 1.3.3

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.