Vulnerability Name: | CVE-2014-3069 (CCN-94839) | ||||||||
Assigned: | 2014-08-07 | ||||||||
Published: | 2014-08-07 | ||||||||
Updated: | 2017-08-29 | ||||||||
Summary: | Multiple CRLF injection vulnerabilities in the Universal Access component in IBM Curam Social Program Management (SPM) 6.0.5.5, when WebSphere Application Server is not used, allow remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified parameters. CWE-93: Improper Neutralization of CRLF Sequences ('CRLF Injection') | ||||||||
CVSS v3 Severity: | 2.6 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 3.5 Low (CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N) 3.0 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N/E:H/RL:OF/RC:C)
3.0 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2014-3069 Source: SECUNIA Type: UNKNOWN 59688 Source: CCN Type: IBM Security Bulletin 1681213 IBM Curam Universal Access V6.0.5.5 can be vulnerable to CRLF Injection attack (CVE-2014-3069) Source: CONFIRM Type: Patch, Vendor Advisory http://www-01.ibm.com/support/docview.wss?uid=swg21681213 Source: CCN Type: BID-69165 IBM Curam Social Program Management CVE-2014-3069 CRLF Injection Vulnerability Source: XF Type: UNKNOWN ibm-curam-cve20143069-csrf(94839) Source: XF Type: UNKNOWN ibm-curam-cve20143069-csrf(94839) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |