First published: Fri Jan 14 2022(Updated: )
Imperva Web Application Firewall (WAF) before 2021-12-23 allows remote unauthenticated attackers to use "Content-Encoding: gzip" to evade WAF security controls and send malicious HTTP POST requests to web servers behind the WAF.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Imperva SecureSphere WAF | <2021-12-23 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-45468 is classified as a critical vulnerability due to its potential for allowing remote unauthenticated attackers to bypass security controls.
To remediate CVE-2021-45468, update your Imperva Web Application Firewall to a version released after December 23, 2021.
CVE-2021-45468 allows attackers to send malicious HTTP POST requests, potentially compromising the security of your web applications.
Yes, CVE-2021-45468 can be exploited by remote unauthenticated attackers, making it particularly dangerous.
CVE-2021-45468 affects all versions of Imperva Web Application Firewall prior to December 23, 2021.