{"api_version":"1","generated_at":"2026-07-23T12:32:33+00:00","cve":"CVE-2019-4461","urls":{"html":"https://cve.report/CVE-2019-4461","api":"https://cve.report/api/cve/CVE-2019-4461.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-4461","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-4461"},"summary":{"title":"CVE-2019-4461","description":"IBM Cloud Orchestrator 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 is vulnerable to HTTP Response Splitting caused by improper caching of content. This would allow the attacker to perform further attacks, such as Web Cache poisoning, cross-site scripting and possibly obtain sensitive information. IBM X-Force ID: 163682.","state":"PUBLIC","assigner":"psirt@us.ibm.com","published_at":"2019-10-25 17:15:00","updated_at":"2020-08-24 17:37:00"},"problem_types":["CWE-74"],"metrics":[],"references":[{"url":"https://www.ibm.com/support/pages/node/1072684","name":"https://www.ibm.com/support/pages/node/1072684","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Security Bulletin: Cacheable HTTPS Response vulnerability affects IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise Edition (CVE-2019-4461)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/163682","name":"ibm-co-cve20194461-response-splitting (163682)","refsource":"XF","tags":["VDB Entry","Vendor Advisory"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-4461","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-4461","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"4461","vulnerable":"1","versionEndIncluding":"2.4.0.5","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"cloud_orchestrator","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"-","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"4461","vulnerable":"1","versionEndIncluding":"2.4.0.5","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"cloud_orchestrator","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"enterprise","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"4461","vulnerable":"1","versionEndIncluding":"2.5.0.9","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"cloud_orchestrator","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"-","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"4461","vulnerable":"1","versionEndIncluding":"2.5.0.9","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"cloud_orchestrator","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"enterprise","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"affects":{"vendor":{"vendor_data":[{"vendor_name":"IBM","product":{"product_data":[{"product_name":"Cloud Orchestrator","version":{"version_data":[{"version_value":"2.4"},{"version_value":"2.4.0.1"},{"version_value":"2.4.0.2"},{"version_value":"2.5"},{"version_value":"2.5.0.1"},{"version_value":"2.4.0.3"},{"version_value":"2.5.0.2"},{"version_value":"2.4.0.4"},{"version_value":"2.5.0.3"},{"version_value":"2.5.0.4"},{"version_value":"2.4.0.5"},{"version_value":"2.5.0.5"},{"version_value":"2.5.0.6"},{"version_value":"2.5.0.7"},{"version_value":"2.5.0.8"},{"version_value":"2.5.0.9"}]}}]}}]}},"CVE_data_meta":{"ID":"CVE-2019-4461","STATE":"PUBLIC","DATE_PUBLIC":"2019-10-23T00:00:00","ASSIGNER":"psirt@us.ibm.com"},"impact":{"cvssv3":{"TM":{"E":"U","RL":"O","RC":"C"},"BM":{"AV":"N","SCORE":"5.400","AC":"L","I":"L","PR":"L","S":"C","C":"L","A":"N","UI":"R"}}},"data_type":"CVE","problemtype":{"problemtype_data":[{"description":[{"value":"Gain Access","lang":"eng"}]}]},"data_format":"MITRE","references":{"reference_data":[{"url":"https://www.ibm.com/support/pages/node/1072684","refsource":"CONFIRM","name":"https://www.ibm.com/support/pages/node/1072684","title":"IBM Security Bulletin 1072684 (Cloud Orchestrator)"},{"title":"X-Force Vulnerability Report","name":"ibm-co-cve20194461-response-splitting (163682)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/163682"}]},"data_version":"4.0","description":{"description_data":[{"value":"IBM Cloud Orchestrator 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 is vulnerable to HTTP Response Splitting caused by improper caching of content. This would allow the attacker to perform further attacks, such as Web Cache poisoning, cross-site scripting and possibly obtain sensitive information. IBM X-Force ID: 163682.","lang":"eng"}]}},"nvd":{"publishedDate":"2019-10-25 17:15:00","lastModifiedDate":"2020-08-24 17:37:00","problem_types":["CWE-74"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.3,"impactScore":2.7},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":3.5},"severity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:ibm:cloud_orchestrator:*:*:*:*:-:*:*:*","versionStartIncluding":"2.4.0.0","versionEndIncluding":"2.4.0.5","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:ibm:cloud_orchestrator:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"2.4.0.0","versionEndIncluding":"2.4.0.5","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:ibm:cloud_orchestrator:*:*:*:*:-:*:*:*","versionStartIncluding":"2.5.0.0","versionEndIncluding":"2.5.0.9","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:ibm:cloud_orchestrator:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"2.5.0.0","versionEndIncluding":"2.5.0.9","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"4461","Ordinal":"142072","Title":"CVE-2019-4461","CVE":"CVE-2019-4461","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"4461","Ordinal":"1","NoteData":"IBM Cloud Orchestrator 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 is vulnerable to HTTP Response Splitting caused by improper caching of content. This would allow the attacker to perform further attacks, such as Web Cache poisoning, cross-site scripting and possibly obtain sensitive information. IBM X-Force ID: 163682.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"4461","Ordinal":"2","NoteData":"2019-10-25","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"4461","Ordinal":"3","NoteData":"2019-10-25","Type":"Other","Title":"Modified"}]}}}