CVE-2013-2950: Code Injection
CRLF injection vulnerability in IBM WebSphere Portal 6.1.0.x before 6.1.0.3 CF26, 6.1.5.x before 6.1.5 CF26, 7.0.0.x before 7.0.0.2 CF21, and 8.0.0.x through 8.0.0.1 CF5, when home substitution (aka uri.home.substitution) is enabled, allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2950?
CVE-2013-2950 is classified as a medium severity vulnerability due to the potential for unauthorized HTTP header injection.
How do I fix CVE-2013-2950?
To address CVE-2013-2950, update IBM WebSphere Portal to version 6.1.0.3 or higher, 6.1.5.0 or higher, 7.0.0.2 or higher, or 8.0.0.2 or higher.
Who is affected by CVE-2013-2950?
CVE-2013-2950 affects users of IBM WebSphere Portal versions 6.1.0.x, 6.1.5.x, 7.0.0.x, and 8.0.0.x prior to their respective fixed versions.
What are the implications of CVE-2013-2950?
If exploited, CVE-2013-2950 can allow authenticated users to inject arbitrary HTTP headers, potentially affecting application security and user privacy.
Is CVE-2013-2950 an on-premise or cloud-related vulnerability?
CVE-2013-2950 is primarily an on-premise vulnerability specific to IBM WebSphere Portal deployments.