CVE-2017-1503: XSS
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is clicked. This would allow the attacker to perform further attacks, such as Web cache poisoning, cross-site scripting, and possibly obtain sensitive information. IBM X-Force ID: 129578.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1503?
CVE-2017-1503 is classified as a high severity vulnerability due to potential exploitation leading to HTTP response splitting attacks.
How do I fix CVE-2017-1503?
To fix CVE-2017-1503, apply the latest security patch or upgrade to a secure version of IBM WebSphere Application Server.
Who is affected by CVE-2017-1503?
CVE-2017-1503 affects IBM WebSphere Application Server versions 7.0, 8.0, 8.5, and 9.0.
What types of attacks can exploit CVE-2017-1503?
CVE-2017-1503 can be exploited through HTTP response splitting attacks that manipulate server responses.
Can CVE-2017-1503 be exploited remotely?
Yes, CVE-2017-1503 can be exploited remotely by attackers using specially-crafted URLs.