First published: Thu Jan 07 2021(Updated: )
IBM Spectrum Protect Plus 10.1.0 through 10.1.6 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. By sending a specially crafted HTTP request, a remote attacker could exploit this vulnerability to inject HTTP HOST header, which will allow the attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 193655.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Spectrum Protect Plus | <=10.1.0-10.1.6 | |
IBM Spectrum Protect Plus | >=10.1.0<10.1.7 | |
Linux Linux kernel |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-5019 is a vulnerability in IBM Spectrum Protect Plus 10.1.0 through 10.1.6 that allows for HTTP header injection.
The vulnerability in CVE-2020-5019 occurs due to improper validation of input by the HOST headers in IBM Spectrum Protect Plus.
An attacker exploiting CVE-2020-5019 can inject HTTP HOST header, potentially leading to various attacks.
IBM has released a patch to address the vulnerability in CVE-2020-5019, so users should update to a version higher than 10.1.6.
More information about CVE-2020-5019 can be found on the IBM X-Force Exchange website and the official IBM support page.