CVE-2018-1474
Last modified
CVE-2018-1474 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 is vulnerable to HTTP response splitting attacks, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to inject arbitrary HTTP headers and cause the server to return a split response, once the URL is clicked. EPSS estimates a 1.16% chance of exploitation in the next 30 days.
Description
IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 is vulnerable to HTTP response splitting attacks, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to inject arbitrary HTTP headers and cause the server to return a split response, once the URL is clicked. This would allow the attacker to perform further attacks, such as Web cache poisoning or cross-site scripting, and possibly obtain sensitive information. IBM X-force ID: 140692.
Metrics
CVSS:3.0/A:N/AC:L/AV:N/C:L/I:L/PR:N/S:C/UI:R/E:U/RC:C/RL:O
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Bigfix Platform | >= 9.2.0, <= 9.2.14 |
| Ibm | Bigfix Platform | >= 9.5, <= 9.5.9 |
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/140692VDB Entry, Vendor Advisory
- https://www.ibm.com/support/docview.wss?uid=ibm10733605Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/140692VDB Entry, Vendor Advisory
- https://www.ibm.com/support/docview.wss?uid=ibm10733605Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-1474?
How severe is CVE-2018-1474?
How do I fix CVE-2018-1474?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-14734drivers/infiniband/core/ucma.c in the Linux kernel through 4…
- CVE-2018-14735An Information Exposure issue was discovered in Hitachi Comm…
- CVE-2018-14736An issue was discovered in libpbc.a in cloudwu PBC through 2…
- CVE-2018-14737An issue was discovered in libpbc.a in cloudwu PBC through 2…
- CVE-2018-14738An issue was discovered in libpbc.a in cloudwu PBC through 2…
- CVE-2018-14739An issue was discovered in libpbc.a in cloudwu PBC through 2…
- CVE-2018-14740An issue was discovered in libpbc.a in cloudwu PBC through 2…
- CVE-2018-14741An issue was discovered in libpbc.a in cloudwu PBC through 2…
- CVE-2018-14742An issue was discovered in libpbc.a in cloudwu PBC through 2…
- CVE-2018-14743An issue was discovered in libpbc.a in cloudwu PBC through 2…
- CVE-2018-14744An issue was discovered in libpbc.a in cloudwu PBC through 2…
- CVE-2018-14745Buffer overflow in prot_get_ring_space in the bcmdhd4358 Wi-…
Are you affected by CVE-2018-1474?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
