IBM Tivoli Integrated Portal CVE-2014-6151 HTTP Response Splitting Vulnerability
BID:70727
Info
IBM Tivoli Integrated Portal CVE-2014-6151 HTTP Response Splitting Vulnerability
| Bugtraq ID: | 70727 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-6151 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 22 2014 12:00AM |
| Updated: | Nov 12 2014 12:57AM |
| Credit: | Lukasz Plonka |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
IBM Tivoli Integrated Portal CVE-2014-6151 HTTP Response Splitting Vulnerability
IBM Tivoli Integrated Portal is prone to an HTTP-response-splitting vulnerability because it fails to properly sanitize user-supplied input.
Attackers can leverage this issue to influence or misrepresent how web content is served, cached, or interpreted. This could aid in various attacks that try to entice client users into a false sense of trust.
Tivoli Integrated Portal 2.2 and prior are vulnerable.
IBM Tivoli Integrated Portal is prone to an HTTP-response-splitting vulnerability because it fails to properly sanitize user-supplied input.
Attackers can leverage this issue to influence or misrepresent how web content is served, cached, or interpreted. This could aid in various attacks that try to entice client users into a false sense of trust.
Tivoli Integrated Portal 2.2 and prior are vulnerable.
Exploit / POC
IBM Tivoli Integrated Portal CVE-2014-6151 HTTP Response Splitting Vulnerability
To exploit this issue an attacker must entice an unsuspecting victim into following a malicious URI.
To exploit this issue an attacker must entice an unsuspecting victim into following a malicious URI.
Solution / Fix
IBM Tivoli Integrated Portal CVE-2014-6151 HTTP Response Splitting Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
IBM Tivoli Integrated Portal CVE-2014-6151 HTTP Response Splitting Vulnerability
References:
References: