First published: Tue Sep 14 2010(Updated: )
CRLF injection vulnerability in load.php in the Local Management Interface (LMI) on the IBM Proventia Network Mail Security System (PNMSS) appliance with firmware before 2.5 allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the javaVersion parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Proventia Network Mail Security System Virtual Appliance | ||
Ibm Proventia Network Mail Security System Virtual Appliance Firmware | =1.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-0155 has a medium severity rating due to its potential for exploitation by authenticated remote users.
To fix CVE-2010-0155, upgrade the firmware of the IBM Proventia Network Mail Security System to version 2.5 or later.
CVE-2010-0155 enables HTTP response splitting attacks through CRLF injection via arbitrary HTTP headers.
CVE-2010-0155 affects users of the IBM Proventia Network Mail Security System and its virtual appliance prior to firmware version 2.5.
Yes, CVE-2010-0155 can be exploited remotely by authenticated users to perform unauthorized actions.