IBM WebSphere Portal HTTP Response Splitting Vulnerability
RISK: Medium Risk
TYPE: Servers - Internet App Servers
A vulnerability has been identified in IBM WebSphere Portal, which can be exploited by malicious people to conduct HTTP response splitting attacks. Certain unspecified input is not properly sanitised before being returned to the user. This can be exploited to insert arbitrary HTTP headers, which will be included in a response sent to the user. Successful exploitation requires that home substitution is enabled (disabled by default).
Impact
- Cross-Site Scripting
- Information Disclosure
System / Technologies affected
- IBM WebSphere Portal 6.1.0.x
- IBM WebSphere Portal 6.1.5.x
- IBM WebSphere Portal 7.0.0.x
- IBM WebSphere Portal 8.0.0.x
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Update to a fixed version (APAR PM85071)
http://www-01.ibm.com/support/docview.wss?uid=swg21638864
Vulnerability Identifier
Source
Related Link
Share with