CVE-2018-1474
IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 is vulnerable to HTTP response splitting attacks, caused by improper validation of user-supplied input.
Does this matter?
Lower severity and a low EPSS score (1.16%). Track it; it rarely justifies an emergency change on its own.
Description
IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 is vulnerable to HTTP response splitting attacks, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to inject arbitrary HTTP headers and cause the server to return a split response, once the URL is clicked. This would allow the attacker to perform further attacks, such as Web cache poisoning or cross-site scripting, and possibly obtain sensitive information. IBM X-force ID: 140692.
- CVSS 3.0
- 4.7 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
- EPSS
- 1.16% probability · 65th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-74
- Affected
- ibm/bigfix platform
- Source
- psirt@us.ibm.com
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/140692VDB Entry, Vendor Advisory
- https://www.ibm.com/support/docview.wss?uid=ibm10733605Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/140692VDB Entry, Vendor Advisory
- https://www.ibm.com/support/docview.wss?uid=ibm10733605Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.