First published: Fri Nov 01 2019(Updated: )
IBM SmartCloud Analytics 1.3.1 through 1.3.5 is vulnerable to possible host header injection attack that could lead to HTTP cache poisoning or firewall bypass. IBM X-Force ID: 159187.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM SmartCloud Analytics Log Analysis | >=1.3.1<=1.3.5 | |
<=1.3.1 | ||
<=1.3.2 | ||
<=1.3.3 | ||
<=1.3.4 | ||
<=1.3.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-4216 refers to a vulnerability in IBM SmartCloud Analytics 1.3.1 through 1.3.5 that could be exploited for a host header injection attack leading to HTTP cache poisoning or firewall bypass.
CVE-2019-4216 has a severity level of 4.6 (medium).
The affected software includes IBM SmartCloud Analytics Log Analysis versions 1.3.1 through 1.3.5.
To fix CVE-2019-4216, it is recommended to update the affected software to a version that is not vulnerable.
More information about CVE-2019-4216 can be found on the IBM X-Force ID: 159187 and the IBM support page.