CVE-2008-4283
Summary
| CVE | CVE-2008-4283 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2009-02-10 22:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | CRLF injection vulnerability in the WebContainer component in IBM WebSphere Application Server (WAS) 5.1.1.19 and earlier 5.1.x versions allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Websphere Application Server | 5.0 | All | All | All |
| Application | Ibm | Websphere Application Server | 5.0 | All | z_os | All |
| Application | Ibm | Websphere Application Server | 5.0.0 | All | All | All |
| Application | Ibm | Websphere Application Server | 5.0.1 | All | All | All |
| Application | Ibm | Websphere Application Server | 5.0.2 | All | All | All |
| Application | Ibm | Websphere Application Server | 5.0.2.1 | All | All | All |
| Application | Ibm | Websphere Application Server | 5.0.2.10 | All | All | All |
| Application | Ibm | Websphere Application Server | 5.0.2.11 | All | All | All |
| Application | Ibm | Websphere Application Server | 5.0.2.12 | All | All | All |
| Application | Ibm | Websphere Application Server | 5.0.2.13 | All | All | All |
| Application | Ibm | Websphere Application Server | 5.0.2.14 | All | All | All |
| Application | Ibm | Websphere Application Server | 5.0.2.15 | All | All | All |
| Application | Ibm | Websphere Application Server | 5.0.2.16 | All | All | All |
| Application | Ibm | Websphere Application Server | 5.0.2.2 | All | All | All |
| Application | Ibm | Websphere Application Server | 5.0.2.3 | All | All | All |
| Application | Ibm | Websphere Application Server | 5.0.2.4 | All | All | All |
| Application | Ibm | Websphere Application Server | 5.0.2.5 | All | All | All |
| Application | Ibm | Websphere Application Server | 5.0.2.6 | All | All | All |
| Application | Ibm | Websphere Application Server | 5.0.2.7 | All | All | All |
| Application | Ibm | Websphere Application Server | 5.0.2.8 | All | All | All |
| Application | Ibm | Websphere Application Server | 5.0.2.9 | All | All | All |
| Application | Ibm | Websphere Application Server | 5.1.0 | All | All | All |
| Application | Ibm | Websphere Application Server | 5.1.0.2 | All | All | All |
| Application | Ibm | Websphere Application Server | 5.1.0.3 | All | All | All |
| Application | Ibm | Websphere Application Server | 5.1.0.4 | All | All | All |
| Application | Ibm | Websphere Application Server | 5.1.0.5 | All | All | All |
| Application | Ibm | Websphere Application Server | 5.1.1 | All | All | All |
| Application | Ibm | Websphere Application Server | 5.1.1.1 | All | All | All |
| Application | Ibm | Websphere Application Server | 5.1.1.10 | All | All | All |
| Application | Ibm | Websphere Application Server | 5.1.1.11 | All | All | All |
| Application | Ibm | Websphere Application Server | 5.1.1.12 | All | All | All |
| Application | Ibm | Websphere Application Server | 5.1.1.13 | All | All | All |
| Application | Ibm | Websphere Application Server | 5.1.1.14 | All | All | All |
| Application | Ibm | Websphere Application Server | 5.1.1.15 | All | All | All |
| Application | Ibm | Websphere Application Server | 5.1.1.16 | All | All | All |
| Application | Ibm | Websphere Application Server | 5.1.1.17 | All | All | All |
| Application | Ibm | Websphere Application Server | 5.1.1.18 | All | All | All |
| Application | Ibm | Websphere Application Server | 5.1.1.2 | All | All | All |
| Application | Ibm | Websphere Application Server | 5.1.1.3 | All | All | All |
| Application | Ibm | Websphere Application Server | 5.1.1.4 | All | All | All |
| Application | Ibm | Websphere Application Server | 5.1.1.5 | All | All | All |
| Application | Ibm | Websphere Application Server | 5.1.1.6 | All | All | All |
| Application | Ibm | Websphere Application Server | 5.1.1.7 | All | All | All |
| Application | Ibm | Websphere Application Server | 5.1.1.8 | All | All | All |
| Application | Ibm | Websphere Application Server | 5.1.1.9 | All | All | All |
| Application | Ibm | Websphere Application Server | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM Error - United States | af854a3a-2127-422b-91ae-364da2661108 | www-1.ibm.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| IBM WebSphere Application Server Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| SE35864 - APPSVR WAS Post 5.1.1.19 ND (/lib V-Z) - PK69929: webcontainer.jar | af854a3a-2127-422b-91ae-364da2661108 | www-1.ibm.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.