CVE-2014-4803: CRLF Injection
CRLF injection vulnerability in the Universal Access implementation in IBM Curam Social Program Management 6.0 SP2 before EP26, 6.0.4 before 6.0.4.5 iFix007, and 6.0.5 before 6.0.5.5 iFix003, when WebSphere Application Server is not used, allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via an unspecified parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4803?
CVE-2014-4803 is classified as a high severity vulnerability due to potential for unauthorized HTTP response manipulation.
How do I fix CVE-2014-4803?
To fix CVE-2014-4803, upgrade IBM Curam Social Program Management to the latest patched version, specifically to 6.0 SP2 EP26 or later.
Who is affected by CVE-2014-4803?
CVE-2014-4803 affects users of IBM Curam Social Program Management versions 6.0 SP2 before EP26, among other specific versions.
What type of vulnerability is CVE-2014-4803?
CVE-2014-4803 is a CRLF injection vulnerability that can be exploited by remote authenticated users.
Can CVE-2014-4803 be exploited without authentication?
No, CVE-2014-4803 requires authentication for exploitation, limiting the attack vector to authenticated users.