First published: Sat Oct 25 2014(Updated: )
CRLF injection vulnerability in IBM Tivoli Integrated Portal (TIP) 2.2.x allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Tivoli Integrated Portal | =2.1 | |
IBM Tivoli Integrated Portal | =2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-6151 has a medium severity rating due to its potential for HTTP response splitting attacks.
To fix CVE-2014-6151, update IBM Tivoli Integrated Portal to a fixed version following the recommendations provided by IBM.
CVE-2014-6151 affects IBM Tivoli Integrated Portal versions 2.1 and 2.2.
CVE-2014-6151 can be exploited to conduct HTTP response splitting attacks.
CVE-2014-6151 is a CRLF injection vulnerability that allows remote authenticated users to inject arbitrary HTTP headers.