First published: Fri Oct 25 2019(Updated: )
IBM Cloud Orchestrator is vulnerable to HTTP Response Splitting caused by improper caching of content. This would allow the attacker to perform further attacks, such as Web Cache poisoning, cross-site scripting and possibly obtain sensitive information.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Cloud Orchestrator Enterprise | >=2.4.0.0<=2.4.0.5 | |
IBM Cloud Orchestrator Enterprise | >=2.4.0.0<=2.4.0.5 | |
IBM Cloud Orchestrator Enterprise | >=2.5.0.0<=2.5.0.9 | |
IBM Cloud Orchestrator Enterprise | >=2.5.0.0<=2.5.0.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-4461 is classified as a moderate severity vulnerability due to its potential for exploitation and impact on data integrity.
To mitigate CVE-2019-4461, upgrade IBM Cloud Orchestrator to a version higher than 2.4.0.5 or 2.5.0.9 where the vulnerability has been addressed.
CVE-2019-4461 could lead to web cache poisoning, cross-site scripting attacks, and exposure of sensitive information.
Versions of IBM Cloud Orchestrator ranging from 2.4.0.0 to 2.4.0.5 and 2.5.0.0 to 2.5.0.9 are affected by CVE-2019-4461.
CVE-2019-4461 does not directly lead to remote code execution but can enable other attacks that may compromise the application.