CVE-2021-39028: Medium severity ibm pub vulnerability
IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 213866.
Other sources
IBM Engineering Lifecycle Optimization - Publishing is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-39028.
What is the title of this vulnerability?
The title of this vulnerability is 'IBM Engineering Lifecycle Optimization - Publishing is vulnerable to HTTP header injection caused by…'
What is the affected software?
The affected software includes IBM Engineering Lifecycle Optimization - Publishing versions 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2.
What is the severity of this vulnerability?
The severity of this vulnerability is medium with a CVSS score of 5.4.
How can this vulnerability be exploited?
This vulnerability can be exploited by conducting various attacks against the vulnerable system, including cross-site scripting (XSS) and HTTP header injection.