Datacap Navigator Vulnerable to HTTP Header Injection
CVE-2024-39736
9.8CRITICAL
What is CVE-2024-39736?
IBM Datacap Navigator versions 9.1.5 through 9.1.9 are exposed to an HTTP header injection vulnerability stemming from inadequate validation of input in the HOST headers. This security flaw could permit an attacker to execute various attacks, such as cross-site scripting, session hijacking, or cache poisoning, potentially compromising the integrity and confidentiality of sensitive information processed by the application. This vulnerability highlights the importance of proper input validation and secure coding practices to mitigate risks associated with web application vulnerabilities.