First published: Thu Oct 08 2020(Updated: )
IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 are vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is clicked. This would allow the attacker to perform further attacks, such as Web cache poisoning, cross-site scripting, and possibly obtain sensitive information. IBM X-Force ID: 165960.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM ISAM | <=9.0.7 | |
IBM Security Verify Access | <=10.0.0 | |
IBM Security Access Manager | >=9.0.7.0<9.0.7.2 | |
IBM Security Verify Access | >=10.0.0<10.0.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-4552.
The severity of CVE-2019-4552 is medium with a severity value of 6.1.
IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 are affected by CVE-2019-4552.
CVE-2019-4552 poses the risk of HTTP response splitting attacks.
CVE-2019-4552 can be exploited by a remote attacker using a specially-crafted URL to cause the server to return a split response.