Lucene search

K
ibmIBMAFC7F6891989929988472E4484D8B25AC7FBCCA340DD73184F71D987BA13551A
HistoryJun 16, 2018 - 10:05 p.m.

Security Bulletin: IBM Security Access Manager Appliance is affected by a HTTPD vulnerability (CVE-2016-8743)

2018-06-1622:05:00
www.ibm.com
101

0.003 Low

EPSS

Percentile

68.0%

Summary

IBM Security Access Manager Appliance has addressed the following vulnerability in the HTTPD libraries used on the appliance.

Vulnerability Details

CVEID: CVE-2016-8743**
DESCRIPTION:** Apache HTTPD is vulnerable to HTTP response splitting attacks, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to inject arbitrary HTTP headers and cause the server to return a split response, once the URL is clicked. This would allow the attacker to perform further attacks, such as Web cache poisoning or cross-site scripting, and possibly obtain sensitive information.
CVSS Base Score: 6.1
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/119917 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)

Affected Products and Versions

Affected IBM Security Access Manager Appliance

|

Affected Versions

—|—
IBM Security Access Manager for Web| 7.0-7.0.0.31

Remediation/Fixes

Product

|

VRMF

|

APAR

|

Remediation

—|—|—|—
IBM Security Access Manager for Web| 7.0 - 7.0.0.31| IJ02932| Upgrade to 7.0.0.34:
7.0.0-ISS-WGA-IF0034

Workarounds and Mitigations

None

CPENameOperatorVersion
ibm security access managereq7.0.0