CVE-2024-39736: IBM Datacap Navigator HTTP HOST header injection
IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 296003.
Other sources
IBM Datacap Navigator is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39736?
CVE-2024-39736 has been classified as a critical vulnerability due to its potential to allow various attacks including cross-site scripting.
How do I fix CVE-2024-39736?
To fix CVE-2024-39736, users should upgrade to the latest version of IBM Datacap Navigator or apply any provided security patches.
Which versions of IBM Datacap are affected by CVE-2024-39736?
CVE-2024-39736 affects IBM Datacap versions 9.1.5 through 9.1.9 inclusive.
What type of attacks can CVE-2024-39736 allow?
CVE-2024-39736 can enable attacks such as HTTP header injection and cross-site scripting.
Is IBM Datacap Navigator vulnerable to CVE-2024-39736?
Yes, IBM Datacap Navigator versions 9.1.5 through 9.1.9 are vulnerable to CVE-2024-39736.