HTTP Response Splitting Vulnerability in IBM Cloud Orchestrator
CVE-2019-4461
What is CVE-2019-4461?
IBM Cloud Orchestrator versions 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 are susceptible to an HTTP Response Splitting vulnerability. This vulnerability arises from improper content caching, enabling attackers to exploit it for malicious purposes, including Web Cache Poisoning and Cross-Site Scripting (XSS). Consequently, attackers may gain access to sensitive information or manipulate content delivered to users. It is crucial for organizations using these versions to implement the necessary fixes as detailed in IBM's advisories.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cloud Orchestrator 2.4
Cloud Orchestrator 2.4.0.1
Cloud Orchestrator 2.4.0.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved