IBM Cloud Orchestrator 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 is vulnerable to HTTP Response Splitting caused by improper caching of content. This would allow the attacker to perform further attacks, such as Web Cache poisoning, cross-site scripting and possibly obtain sensitive information. IBM X-Force ID: 163682.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: ibm
Published: 2019-10-25T16:30:37.444055Z
Updated: 2024-09-17T00:05:28.708Z
Reserved: 2019-01-03T00:00:00
Link: CVE-2019-4461
Vulnrichment
No data.
NVD
Status : Modified
Published: 2019-10-25T17:15:11.710
Modified: 2024-11-21T04:43:38.210
Link: CVE-2019-4461
Redhat
No data.