Lucene search

K
ibmIBM7CE4EB7E1D672BBA32393938186B4F802DBDA1E4331885737A51E4F71F248601
HistoryMar 30, 2023 - 7:17 p.m.

Security Bulletin: IBM UrbanCode Deploy (UCD) is vulnerable to HTTP response splitting due to Netty (CVE-2022-41915)

2023-03-3019:17:10
www.ibm.com
7
ibm urbancode deploy
netty
http response splitting
cve-2022-41915
vulnerability
network communication
affected products
versions
remediation
upgrades
security bulletin
cross-site scripting

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

0.002 Low

EPSS

Percentile

57.6%

Summary

Netty is used by IBM UrbanCode Deploy (UCD) for network communication. An attacker may be able to inject HTTP/1.1 response header and cause the server to return a split resonse. (CVE-2022-41915)

Vulnerability Details

CVEID:CVE-2022-41915
**DESCRIPTION:**Netty is vulnerable to HTTP response splitting attacks, caused by a flaw when calling DefaultHttpHeaders.set with an iterator of values. A remote attacker could exploit this vulnerability to inject arbitrary HTTP/1.1 response header in some form and cause the server to return a split response, once the URL is clicked. This would allow the attacker to perform further attacks, such as Web cache poisoning or cross-site scripting, and possibly obtain sensitive information.
CVSS Base score: 6.5
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/242595 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
UCD - IBM UrbanCode Deploy 6.2 - 6.2.7.19
UCD - IBM UrbanCode Deploy 7.0 - 7.0.5.14
UCD - IBM UrbanCode Deploy 7.1 - 7.1.2.10
UCD - IBM UrbanCode Deploy 7.2 - 7.2.3.3
UCD - IBM UrbanCode Deploy 7.3 - 7.3.0.1

Remediation/Fixes

IBM strongly suggests the following:

Upgrade to any of 6.2.7.20,7.0.5.15, 7.1.2.11, 7.2.3.4, or 7.3.1.0 or later

Workarounds and Mitigations

None

Affected configurations

Vulners
Node
ibmurbancode_deployMatch7.3.1.0
CPENameOperatorVersion
ibm urbancode deployeq7.3.1.0

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

0.002 Low

EPSS

Percentile

57.6%