Lucene search

K
ibmIBME97BC3D62F27454A2D367688620F1E59732C4FA0B1C4E85EE196731BFFB1EE13
HistoryJun 12, 2020 - 10:03 p.m.

Security Bulletin: Vulnerability in Go programming language affects IBM Spectrum Protect Server (CVE-2019-16276)

2020-06-1222:03:29
www.ibm.com
15

EPSS

0.012

Percentile

85.7%

Summary

The Go programming language could allow a remote attacker to bypass security restrictions which affects the IBM Spectrum Protect Server.

Vulnerability Details

CVEID:CVE-2019-16276
**DESCRIPTION:**Golang could allow a remote attacker to bypass security restrictions, caused by improper validation of HTTP header. By sending a specially-crafted request, an attacker could exploit this vulnerability to bypass filter or conduct HTTP request smuggling.
CVSS Base score: 5.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/167963 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Spectrum Protect Server 8.1.0.000-8.1.9.300

Remediation/Fixes

Spectrum Protect Server Release First Fixing VRM Level Platform Link to Fix
8.1 8.1.10.000 AIX
Linux
Windows <http://www.ibm.com/support/pages/node/6229034&gt;

Workarounds and Mitigations

None