CVE-2014-3012: CRLF Injection
Multiple CRLF injection vulnerabilities in IBM Curam Social Program Management 5.2 SP1 through 6.0.5.4 allow remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified parameters to custom JSPs.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3012?
CVE-2014-3012 has a moderate severity level as it allows authenticated users to perform HTTP response splitting attacks.
How do I fix CVE-2014-3012?
To fix CVE-2014-3012, apply the latest patches provided by IBM for affected versions of IBM Curam Social Program Management.
What products are affected by CVE-2014-3012?
CVE-2014-3012 affects IBM Curam Social Program Management versions from 5.2 SP1 through 6.0.5.4.
Can CVE-2014-3012 affect my web application security?
Yes, CVE-2014-3012 can compromise web application security by allowing injection of arbitrary HTTP headers.
Is CVE-2014-3012 a common issue in web applications?
CVE-2014-3012 reflects a common issue with CRLF injection vulnerabilities found in various web applications.