HTTP Response Splitting Vulnerability in IBM Cloud Orchestrator
CVE-2019-4396

5.4MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
25 October 2019

Summary

IBM Cloud Orchestrator versions 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 are exposed to HTTP response splitting attacks due to inadequate validation of user-supplied input. This vulnerability enables remote attackers to inject malicious HTTP headers, which can lead the server to issue a split response when a crafted URL is accessed. Exploiting this can facilitate various secondary attacks, such as web cache poisoning and cross-site scripting, potentially compromising sensitive information. For more details, refer to the IBM X-Force ID: 162236.

Affected Version(s)

Cloud Orchestrator 2.4

Cloud Orchestrator 2.4.0.1

Cloud Orchestrator 2.4.0.2

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.