Vulnerability Description
IBM Cloud Orchestrator 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 is vulnerable to HTTP Response Splitting caused by improper caching of content. This would allow the attacker to perform further attacks, such as Web Cache poisoning, cross-site scripting and possibly obtain sensitive information. IBM X-Force ID: 163682.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Cloud Orchestrator | >= 2.4.0.0, <= 2.4.0.5 |
Related Weaknesses (CWE)
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/163682VDB EntryVendor Advisory
- https://www.ibm.com/support/pages/node/1072684Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/163682VDB EntryVendor Advisory
- https://www.ibm.com/support/pages/node/1072684Vendor Advisory
FAQ
What is CVE-2019-4461?
CVE-2019-4461 is a vulnerability with a CVSS score of 5.4 (MEDIUM). IBM Cloud Orchestrator 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 is vulnerable to HTTP Response Splitting caused by improper caching of content. This would allow the attacker to perform further atta...
How severe is CVE-2019-4461?
CVE-2019-4461 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-4461?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Cloud Orchestrator.