IBM InfoSphere BigInsights CVE-2013-3998 HTTP Response Splitting Vulnerability
BID:66359
Info
IBM InfoSphere BigInsights CVE-2013-3998 HTTP Response Splitting Vulnerability
| Bugtraq ID: | 66359 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-3998 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 20 2014 12:00AM |
| Updated: | Mar 20 2014 12:00AM |
| Credit: | IBM |
| Vulnerable: |
IBM InfoSphere BigInsights 2.1 IBM InfoSphere BigInsights 2.0 IBM InfoSphere BigInsights 1.4 IBM InfoSphere BigInsights 1.3.0.1 IBM InfoSphere BigInsights 1.3 IBM InfoSphere BigInsights 1.2 IBM InfoSphere BigInsights 1.1.0.2 IBM InfoSphere BigInsights 1.1.0.1 IBM InfoSphere BigInsights 1.1 |
| Not Vulnerable: | |
Discussion
IBM InfoSphere BigInsights CVE-2013-3998 HTTP Response Splitting Vulnerability
IBM InfoSphere BigInsights is prone to an HTTP-response-splitting vulnerability because it fails to properly sanitize user-supplied input.
Attackers can leverage this issue to influence or misrepresent how web content is served, cached, or interpreted. This could aid in various attacks that try to entice client users into a false sense of trust.
IBM InfoSphere BigInsights 1.1 through versions 2.1 are vulnerable.
IBM InfoSphere BigInsights is prone to an HTTP-response-splitting vulnerability because it fails to properly sanitize user-supplied input.
Attackers can leverage this issue to influence or misrepresent how web content is served, cached, or interpreted. This could aid in various attacks that try to entice client users into a false sense of trust.
IBM InfoSphere BigInsights 1.1 through versions 2.1 are vulnerable.
Exploit / POC
IBM InfoSphere BigInsights CVE-2013-3998 HTTP Response Splitting Vulnerability
To exploit this issue an attacker must entice an unsuspecting victim into following a malicious URI.
To exploit this issue an attacker must entice an unsuspecting victim into following a malicious URI.
Solution / Fix
IBM InfoSphere BigInsights CVE-2013-3998 HTTP Response Splitting Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
IBM InfoSphere BigInsights CVE-2013-3998 HTTP Response Splitting Vulnerability
References:
References: