VulnerabilityModified
CVE-2014-3021
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.35, 8.0 before 8.0.0.10, and 8.5 before 8.5.5.4 does not properly handle HTTP headers, which allows remote attackers to obtain sensitive cookie and authentication data via an unspecified HTTP method.
MEDIUM 5.0EPSS 2.23%
Does this matter?
Lower severity and a low EPSS score (2.23%). Track it; it rarely justifies an emergency change on its own.
Description
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.35, 8.0 before 8.0.0.10, and 8.5 before 8.5.5.4 does not properly handle HTTP headers, which allows remote attackers to obtain sensitive cookie and authentication data via an unspecified HTTP method.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 2.23% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- ibm/websphere application server
- Source
- psirt@us.ibm.com
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1PI08268
- http://www-01.ibm.com/support/docview.wss?uid=swg21684612Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/93059
- http://www-01.ibm.com/support/docview.wss?uid=swg1PI08268
- http://www-01.ibm.com/support/docview.wss?uid=swg21684612Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/93059
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.