HTTP Header Injection Vulnerability in IBM DataPower Gateway
CVE-2021-38944

4.8MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
18 May 2022

Summary

IBM DataPower Gateway is vulnerable to an HTTP header injection issue due to improper input validation of HOST headers. This vulnerability can be exploited by attackers to launch various attacks such as cross-site scripting and session hijacking, compromising the security of the affected system. Organizations using IBM DataPower Gateway versions 10.0.2.0 through 1.0.3.0 and 2018.4.1.0 through 2018.4.1.18 should take necessary actions to mitigate potential risks.

Affected Version(s)

DataPower Gateway 2018.4.1.0

DataPower Gateway 10.0.1.0

DataPower Gateway 10.0.2.0

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.