HTTP Header Injection Vulnerability in IBM DataPower Gateway
CVE-2021-38944
4.8MEDIUM
What is CVE-2021-38944?
IBM DataPower Gateway is vulnerable to an HTTP header injection issue due to improper input validation of HOST headers. This vulnerability can be exploited by attackers to launch various attacks such as cross-site scripting and session hijacking, compromising the security of the affected system. Organizations using IBM DataPower Gateway versions 10.0.2.0 through 1.0.3.0 and 2018.4.1.0 through 2018.4.1.18 should take necessary actions to mitigate potential risks.
Affected Version(s)
DataPower Gateway 2018.4.1.0
DataPower Gateway 10.0.1.0
DataPower Gateway 10.0.2.0