CRLF injection vulnerability in the WebContainer component in IBM WebSphere Application Server (WAS) 5.1.1.19 and earlier 5.1.x versions allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 00:51
Type | Values Removed | Values Added |
---|---|---|
References | () http://www-1.ibm.com/support/docview.wss?uid=isg1SE35864 - Vendor Advisory | |
References | () http://www-1.ibm.com/support/docview.wss?uid=swg1PK69929 - | |
References | () http://www.securityfocus.com/bid/33700 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/47199 - |
Information
Published : 2009-02-10 22:30
Updated : 2025-04-09 00:30
NVD link : CVE-2008-4283
Mitre link : CVE-2008-4283
CVE.ORG link : CVE-2008-4283
JSON object : View
Products Affected
ibm
- websphere_application_server
CWE
CWE-20
Improper Input Validation