CVE-2021-29854: High severity IBM Maximo Asset Management vulnerability
IBM Maximo Asset Management 7.6.1.1 and 7.6.1.2 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. By sending a specially crafted HTTP request, a remote attacker could exploit this vulnerability to inject HTTP HOST header, which will allow the attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 205680.
Other sources
IBM Maximo Asset Management is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. By sending a specially crafted HTTP request, a remote attacker could exploit this vulnerability to inject HTTP HOST header, which will allow the attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-29854.
What is the severity level of CVE-2021-29854?
The severity level of CVE-2021-29854 is high with a severity value of 7.2.
Which IBM Maximo Asset Management versions are affected by CVE-2021-29854?
IBM Maximo Asset Management versions 7.6.1.1 and 7.6.1.2 are affected by CVE-2021-29854.
How can an attacker exploit CVE-2021-29854 vulnerability?
An attacker can exploit CVE-2021-29854 by sending a specially crafted HTTP request to inject HTTP HOST header.
Are there any references for CVE-2021-29854 vulnerability?
Yes, you can find more information about CVE-2021-29854 vulnerability at the following references: [Reference 1](https://exchange.xforce.ibmcloud.com/vulnerabilities/205680) [Reference 2](https://www.ibm.com/support/pages/node/6579187)