CVE-2019-4186
CVE-2019-4186
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 5.3EPSS 1.6%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
05 sep 2019Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
IBM Jazz for Service Management 1.1.3 is vulnerable to HTTP header injection, caused by incorrect trust in the HTTP Host header during caching. By sending a specially crafted HTTP GET request, a remote attacker could exploit this vulnerability to inject arbitrary HTTP headers, which will allow the attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-force ID: 158976.
CVSS:3.0/AC:L/AV:N/UI:N/A:N/I:L/PR:N/C:N/S:U/E:U/RC:C/RL:O
Productos afectados
IBM · Jazz for Service Management¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →