CVE-2017-1262: Medium severity ibm infosphere guardium z/os vulnerability
IBM Security Guardium 10.0 is vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is clicked. This would allow the attacker to perform further attacks, such as Web cache poisoning, cross-site scripting, and possibly obtain sensitive information. IBM X-Force ID: 124737.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1262?
CVE-2017-1262 has a medium severity rating due to the potential for HTTP response splitting attacks.
How do I fix CVE-2017-1262?
To mitigate CVE-2017-1262, apply the latest patches provided by IBM for the affected versions of Security Guardium.
Which versions are affected by CVE-2017-1262?
CVE-2017-1262 affects IBM Security Guardium versions 10.0, 10.0.1, 10.1.0, 10.1.2, and 10.1.3.
What can an attacker do with CVE-2017-1262?
An attacker exploiting CVE-2017-1262 can cause the server to return a split HTTP response, facilitating further attacks.
Is there a workaround for CVE-2017-1262?
Currently, the recommended action is to update to the latest version of IBM Security Guardium, as a direct workaround is not specified.