Lucene search

K
ibmIBM6B2538F7D01FCFEC4788FC75C9A7DFF9351B8967A9455039C70241DCDEAE06E1
HistoryOct 23, 2019 - 7:20 p.m.

Security Bulletin: Cacheable HTTPS Response vulnerability affects IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise Edition (CVE-2019-4461)

2019-10-2319:20:17
www.ibm.com
9

0.001 Low

EPSS

Percentile

19.6%

Summary

IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise has identified and addressed the Cacheable HTTPS Response vulnerability.

Vulnerability Details

CVEID: CVE-2019-4461 DESCRIPTION: IBM Cloud Orchestrator is vulnerable to HTTP Response Splitting caused by improper caching of content. This would allow the attacker to perform further attacks, such as Web Cache poisoning, cross-site scripting and possibly obtain sensitive information.
CVSS Base Score: 5.4
CVSS Temporal Score: See <https://exchange.xforce.ibmcloud.com/vulnerabilities/163682&gt; for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N)

Affected Products and Versions

IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise 2.5, 2.5.0.1, 2.5.0.2, 2.5.0.3, 2.5.0.4, 2.5.0.5, 2.5.0.6, 2.5.0.7, 2.5.0.8, 2.5.0.9

IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise 2.4, 2.4.0.1, 2.4.0.2, 2.4.0.3, 2.4.0.4, 2.4.0.5

Remediation/Fixes

The recommended solution is to apply the fixes as soon as practical.

Principal Product and Version(s) VRMF Remediation/First Fix
IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise 2.5, 2.5.0.1, 2.5.0.2, 2.5.0.3, 2.5.0.4, 2.5.0.5, 2.5.0.6, 2.5.0.7, 2.5.0.8, 2.5.0.9

For 2.5 versions, IBM recommends upgrading to Fix Pack 10 (2.5.0.10) of IBM Cloud Orchestrator.

<https://www-01.ibm.com/support/docview.wss?uid=ibm10888201&gt;

IBM Cloud Orchestrator and IBM Cloud Orchestrator Enterprise | 2.4, 2.4.0.1, 2.4.0.2, 2.4.0.3, 2.4.0.4, 2.4.0.5 |

Contact IBM Cloud Orchestrator support.

Workarounds and Mitigations

None

0.001 Low

EPSS

Percentile

19.6%

Related for 6B2538F7D01FCFEC4788FC75C9A7DFF9351B8967A9455039C70241DCDEAE06E1