IBM WebSphere Portal CVE-2013-2950 HTTP Response Splitting Vulnerability
BID:60201
Info
IBM WebSphere Portal CVE-2013-2950 HTTP Response Splitting Vulnerability
| Bugtraq ID: | 60201 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-2950 |
| Remote: | Yes |
| Local: | No |
| Published: | May 28 2013 12:00AM |
| Updated: | May 28 2013 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
IBM Websphere Portal 8.0 IBM Websphere Portal 7.0 IBM Websphere Portal 6.1.5 IBM Websphere Portal 6.1 |
| Not Vulnerable: | |
Discussion
IBM WebSphere Portal CVE-2013-2950 HTTP Response Splitting Vulnerability
IBM WebSphere Portal is prone to an HTTP response-splitting vulnerability because it fails to sufficiently sanitize user-supplied data.
Attackers can leverage this issue to influence or misrepresent how web content is served, cached, or interpreted. This could aid in various attacks that try to entice client users into a false sense of trust.
IBM WebSphere Portal is prone to an HTTP response-splitting vulnerability because it fails to sufficiently sanitize user-supplied data.
Attackers can leverage this issue to influence or misrepresent how web content is served, cached, or interpreted. This could aid in various attacks that try to entice client users into a false sense of trust.
Exploit / POC
IBM WebSphere Portal CVE-2013-2950 HTTP Response Splitting Vulnerability
To exploit this issue an attacker must entice an unsuspecting victim into following a malicious URI.
To exploit this issue an attacker must entice an unsuspecting victim into following a malicious URI.
Solution / Fix
IBM WebSphere Portal CVE-2013-2950 HTTP Response Splitting Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
IBM WebSphere Portal CVE-2013-2950 HTTP Response Splitting Vulnerability
References:
References: