Lucene search

K
nvd[email protected]NVD:CVE-2010-0155
HistorySep 14, 2010 - 5:00 p.m.

CVE-2010-0155

2010-09-1417:00:01
CWE-94
web.nvd.nist.gov
1

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

AI Score

6.4

Confidence

Low

EPSS

0.001

Percentile

36.0%

CRLF injection vulnerability in load.php in the Local Management Interface (LMI) on the IBM Proventia Network Mail Security System (PNMSS) appliance with firmware before 2.5 allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the javaVersion parameter.

Affected configurations

Nvd
Node
ibmproventia_network_mail_security_system_virtual_appliance
AND
ibmproventia_network_mail_security_system_virtual_appliance_firmwareMatch1.6
VendorProductVersionCPE
ibmproventia_network_mail_security_system_virtual_appliance*cpe:2.3:a:ibm:proventia_network_mail_security_system_virtual_appliance:*:*:*:*:*:*:*:*
ibmproventia_network_mail_security_system_virtual_appliance_firmware1.6cpe:2.3:a:ibm:proventia_network_mail_security_system_virtual_appliance_firmware:1.6:*:*:*:*:*:*:*

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

AI Score

6.4

Confidence

Low

EPSS

0.001

Percentile

36.0%