HTTP Response Splitting Vulnerability in IBM Cloud Orchestrator
CVE-2019-4396
5.4MEDIUM
Summary
IBM Cloud Orchestrator versions 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 are exposed to HTTP response splitting attacks due to inadequate validation of user-supplied input. This vulnerability enables remote attackers to inject malicious HTTP headers, which can lead the server to issue a split response when a crafted URL is accessed. Exploiting this can facilitate various secondary attacks, such as web cache poisoning and cross-site scripting, potentially compromising sensitive information. For more details, refer to the IBM X-Force ID: 162236.
Affected Version(s)
Cloud Orchestrator 2.4
Cloud Orchestrator 2.4.0.1
Cloud Orchestrator 2.4.0.2
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved