First published: Mon Apr 08 2019(Updated: )
IBM Cloud Private 3.1.0 and 3.1.1 is vulnerable to HTTP HOST header injection, caused by improper validation of input. By persuading a victim to visit a specially-crafted Web page, a remote attacker could exploit this vulnerability to inject arbitrary HTTP headers, which will allow the attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 153385.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cloud Private | =3.1.0 | |
IBM Cloud Private | =3.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-1943 is medium with a CVSS score of 5.4.
CVE-2018-1943 affects IBM Cloud Private versions 3.1.0 and 3.1.1.
CVE-2018-1943 is a vulnerability in IBM Cloud Private that allows remote attackers to inject arbitrary HTTP headers through improper validation of input, potentially leading to HTTP HOST header injection.
CVE-2018-1943 can be exploited by persuading a victim to visit a specially-crafted web page.
Yes, references for CVE-2018-1943 can be found at the following links: [SecurityFocus](http://www.securityfocus.com/bid/107828), [IBM X-Force](https://exchange.xforce.ibmcloud.com/vulnerabilities/153385), [IBM Support](https://www.ibm.com/support/docview.wss?uid=ibm10871656).