CVE-2014-9564
Summary
| CVE | CVE-2014-9564 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-08-25 18:29:00 UTC |
| Updated | 2017-08-30 13:49:00 UTC |
| Description | CRLF injection vulnerability in IBM Flex System EN6131 40Gb Ethernet and IB6131 40Gb Infiniband Switch firmware before 3.4.1110 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks and resulting web cache poisoning or cross-site scripting (XSS) attacks, or obtain sensitive information via multiple unspecified parameters. |
Risk And Classification
Problem Types: CWE-93
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Ibm | En6131 | - | All | All | All |
| Hardware | Ibm | En6131 | - | All | All | All |
| Operating System | Ibm | En6131 Firmware | - | All | All | All |
| Operating System | Ibm | En6131 Firmware | - | All | All | All |
| Hardware | Ibm | Ib6131 | - | All | All | All |
| Hardware | Ibm | Ib6131 | - | All | All | All |
| Operating System | Ibm | Ib6131 Firmware | - | All | All | All |
| Operating System | Ibm | Ib6131 Firmware | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM Support | CONFIRM | www.ibm.com | Vendor Advisory |
| Multiple IBM Flex System Products CVE-2014-9564 HTTP Response Splitting Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.