CVE-2018-1474: Medium severity IBM BigFix Platform vulnerability
IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 is vulnerable to HTTP response splitting attacks, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to inject arbitrary HTTP headers and cause the server to return a split response, once the URL is clicked. This would allow the attacker to perform further attacks, such as Web cache poisoning or cross-site scripting, and possibly obtain sensitive information. IBM X-force ID: 140692.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1474?
CVE-2018-1474 has a moderate severity rating due to its potential to allow HTTP response splitting attacks.
How do I fix CVE-2018-1474?
To fix CVE-2018-1474, upgrade IBM BigFix Platform to versions 9.2.15 or later, or 9.5.10 or later.
What software is affected by CVE-2018-1474?
CVE-2018-1474 affects IBM BigFix Platform versions 9.2.0 through 9.2.14 and 9.5 through 9.5.9.
Can CVE-2018-1474 lead to unauthorized access?
Yes, CVE-2018-1474 can allow a remote attacker to inject arbitrary HTTP headers, potentially leading to unauthorized access.
Is user input validation the only issue with CVE-2018-1474?
Yes, the vulnerability arises specifically from improper validation of user-supplied input.