HTTP Header Injection Vulnerability in IBM DataPower Gateway
CVE-2021-38944
4.8MEDIUM
Summary
IBM DataPower Gateway is vulnerable to an HTTP header injection issue due to improper input validation of HOST headers. This vulnerability can be exploited by attackers to launch various attacks such as cross-site scripting and session hijacking, compromising the security of the affected system. Organizations using IBM DataPower Gateway versions 10.0.2.0 through 1.0.3.0 and 2018.4.1.0 through 2018.4.1.18 should take necessary actions to mitigate potential risks.
Affected Version(s)
DataPower Gateway 2018.4.1.0
DataPower Gateway 10.0.1.0
DataPower Gateway 10.0.2.0
References
CVSS V3.1
Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved