IBM Lotus Expeditor Request Header Spoofing Security Bypass Vulnerability
BID:54163
Info
IBM Lotus Expeditor Request Header Spoofing Security Bypass Vulnerability
| Bugtraq ID: | 54163 |
| Class: | Design Error |
| CVE: |
CVE-2012-0191 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 22 2012 12:00AM |
| Updated: | May 31 2013 02:44PM |
| Credit: | IBM |
| Vulnerable: |
IBM WebSphere Commerce 7.0 |
| Not Vulnerable: | |
Discussion
IBM Lotus Expeditor Request Header Spoofing Security Bypass Vulnerability
IBM Lotus Expeditor is prone to a security-bypass that allows attackers to spoof request headers.
An attacker can exploit this issue to bypass certain security restrictions by spoofing request headers allowing the attacker to perform malicious activities. Other attacks may also be possible.
IBM Lotus Expeditor is prone to a security-bypass that allows attackers to spoof request headers.
An attacker can exploit this issue to bypass certain security restrictions by spoofing request headers allowing the attacker to perform malicious activities. Other attacks may also be possible.
Exploit / POC
IBM Lotus Expeditor Request Header Spoofing Security Bypass Vulnerability
Attackers can exploit this issue with readily available tools.
Attackers can exploit this issue with readily available tools.
Solution / Fix
IBM Lotus Expeditor Request Header Spoofing Security Bypass Vulnerability
Solution:
Updates are available; please see the references for more information.
Solution:
Updates are available; please see the references for more information.
References
IBM Lotus Expeditor Request Header Spoofing Security Bypass Vulnerability
References:
References: