CVE-2007-1608: CRLF Injection
Published Mar 22, 2007
·Updated
CRLF injection vulnerability in IBM WebSphere Application Server (WAS) before 6.0.2.19 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a single CRLF sequence in a context that is not a valid multi-line header.
Affected Software
1 affected component
IBM WebSphere Application Server Feature Pack for Web Services<=6.0.2.15
Remediation
Patch Available
Event History
Mar 22, 2007
CVE Published
11:19 PM
Mar 23, 2007
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-1608?
CVE-2007-1608 has a medium severity rating, allowing potential HTTP response splitting attacks.
2
How do I fix CVE-2007-1608?
To fix CVE-2007-1608, upgrade IBM WebSphere Application Server to version 6.0.2.19 or later.
3
What versions of IBM WebSphere Application Server are affected by CVE-2007-1608?
CVE-2007-1608 affects IBM WebSphere Application Server versions prior to 6.0.2.19.
4
Can CVE-2007-1608 lead to data exposure?
Yes, CVE-2007-1608 can potentially allow unauthorized data exposure through HTTP response splitting.
5
Who is vulnerable to CVE-2007-1608?
Organizations using IBM WebSphere Application Server versions up to 6.0.2.15 are vulnerable to CVE-2007-1608.