CVE-2014-3069: CRLF Injection
Multiple CRLF injection vulnerabilities in the Universal Access component in IBM Curam Social Program Management (SPM) 6.0.5.5, when WebSphere Application Server is not used, allow remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified parameters.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3069?
CVE-2014-3069 is considered a medium severity vulnerability due to its potential for HTTP response splitting attacks.
How do I fix CVE-2014-3069?
To fix CVE-2014-3069, it is recommended to upgrade IBM Curam Social Program Management to a patched version or configure it to run with WebSphere Application Server.
Who is affected by CVE-2014-3069?
Users of IBM Curam Social Program Management version 6.0.5.5 without WebSphere Application Server are affected by CVE-2014-3069.
What types of attacks can CVE-2014-3069 enable?
CVE-2014-3069 can enable remote authenticated users to perform HTTP response splitting attacks.
Is CVE-2014-3069 a network vulnerability?
Yes, CVE-2014-3069 is a network vulnerability that impacts web applications and allows for the injection of arbitrary HTTP headers.