Lucene search

K
ibmIBM70F04B9A5CE3FFBC33D36A32D999163F5334E04B121B116CCEE525F5C79AD71C
HistoryJun 15, 2018 - 10:49 p.m.

Security Bulletin: Vulnerability in Apache Tomcat afffects IBM Algorithmics One-Algo Risk Application (CVE-2016-6816)

2018-06-1522:49:25
www.ibm.com
18

0.003 Low

EPSS

Percentile

66.0%

Summary

Apache Tomcat is vulnerable to HTTP response splitting attacks, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to inject arbitrary HTTP headers and cause the server to return a split response, once the URL is clicked. This would allow the attacker to perform further attacks, such as Web cache poisoning or cross-site scripting, and possibly obtain sensitive information.

Vulnerability Details

CVE-ID: CVE-2016-6816 Description: Apache Tomcat is vulnerable to HTTP response splitting attacks, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to inject arbitrary HTTP headers and cause the server to return a split response, once the URL is clicked. This would allow the attacker to perform further attacks, such as Web cache poisoning or cross-site scripting, and possibly obtain sensitive information.
CVSS Base Score: 6.100
CVSS Temporal Score: https://exchange.xforce.ibmcloud.com/vulnerabilities/119158 for more information
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)

Affected Products and Versions

Algo One Algo Risk Application (ARA) versions 5.1.0, 5.0.0, 4.9.1.

Apache Tomcat is not packaged with Algo One Algo Risk Application 5.1.0.

Remediation/Fixes

Product Name

| iFix Name|Remediation/First Fix
—|—|—
Algo One ARA| 5.1.0.0| <https://support.podc.sl.edst.ibm.com/support/home/product/D840645J54788H24/Algo_One&gt;
Algo One ARA| 5.0.0.6-17| _http://www.ibm.com/support/fixcentral/swg/quickorder?parent=ibm~Information+Management&product=ibm/Information+Management/Algo+One&release=All&platform=All&function=fixId&fixids=5.0.0.5006-17-Algo-One-ARA-if0344:0&includeSupersedes=0&source=fc&login=true _
Algo One ARA| 4.9.1.1-22| _http://www.ibm.com/support/fixcentral/swg/quickorder?parent=ibm~Information+Management&product=ibm/Information+Management/Algo+One&release=All&platform=All&function=fixId&fixids=4.9.1.4911-22-Algo-One-ARA-if0048:0&includeSupersedes=0&source=fc&login=true _
Algo One ARA| 4.9.1.0-17| http://www.ibm.com/support/fixcentral/swg/quickorder?parent=ibm~Information+Management&product=ibm/Information+Management/Algo+One&release=All&platform=All&function=fixId&fixids=4.9.1.4910-17-Algo-One-ARA-if0049:0&includeSupersedes=0&source=fc&login=true

CPENameOperatorVersion
algo oneeq5.1.0
algo oneeq5.0
algo oneeq4.9.1