CVE-2023-47143: IBM Tivoli Application Dependency Discovery Manager HOST header injection
IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 270270.
Other sources
IBM Tivoli Application Dependency Discovery Manager is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-47143?
CVE-2023-47143 is considered a moderate severity vulnerability due to the potential for HTTP header injection.
How do I fix CVE-2023-47143?
To fix CVE-2023-47143, upgrade IBM Tivoli Application Dependency Discovery Manager to version 7.3.0.11 or higher.
What are the impacts of CVE-2023-47143?
The impacts of CVE-2023-47143 include potential cross-site scripting and other attacks that can exploit improper validation of HOST headers.
Which versions of IBM Tivoli Application Dependency Discovery Manager are affected by CVE-2023-47143?
IBM Tivoli Application Dependency Discovery Manager versions 7.3.0.0 through 7.3.0.10 are affected by CVE-2023-47143.
Is CVE-2023-47143 exploitable?
Yes, CVE-2023-47143 is exploitable if an attacker sends specially crafted requests to the vulnerable server.