Lucene search

K
nvd[email protected]NVD:CVE-2015-2028
HistoryOct 04, 2015 - 2:59 a.m.

CVE-2015-2028

2015-10-0402:59:12
web.nvd.nist.gov
2

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6.7

Confidence

Low

EPSS

0.002

Percentile

56.6%

CRLF injection vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL.

Affected configurations

Nvd
Node
ibmwebsphere_extreme_scaleMatch7.1.0
OR
ibmwebsphere_extreme_scaleMatch7.1.0.2
OR
ibmwebsphere_extreme_scaleMatch7.1.1
VendorProductVersionCPE
ibmwebsphere_extreme_scale7.1.0cpe:2.3:a:ibm:websphere_extreme_scale:7.1.0:*:*:*:*:*:*:*
ibmwebsphere_extreme_scale7.1.0.2cpe:2.3:a:ibm:websphere_extreme_scale:7.1.0.2:*:*:*:*:*:*:*
ibmwebsphere_extreme_scale7.1.1cpe:2.3:a:ibm:websphere_extreme_scale:7.1.1:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

6.7

Confidence

Low

EPSS

0.002

Percentile

56.6%

Related for NVD:CVE-2015-2028