← Back

CVE-2021-29872

nvd nist
Published: Jan 18, 2022Modified: Nov 21, 2024

JSON object

Loading...
5.4
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD

Description

IBM Cloud Pak for Automation 21.0.1 and 21.0.2 - Business Automation Studio Component is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. By sending a specially crafted HTTP request, a remote attacker could exploit this vulnerability to inject HTTP HOST header, which will allow the attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 206228.

Affected (16)

1 product
Cloud Pak For Automation
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Ibm
Before 21.0.2
Version 21.0.2
Version 21.0.2 interim_fix001
Version 21.0.2 interim_fix002
Version 21.0.2 interim_fix003
Version 21.0.2 interim_fix004
Version 21.0.2 interim_fix005
Version 21.0.2 interim_fix006
Configuration B
8 vulnerable
Vulnerable SoftwareAffected Versions
Ibm
Before 21.0.1
Version 21.0.1
Version 21.0.1 interim_fix001
Version 21.0.1 interim_fix002
Version 21.0.1 interim_fix003
Version 21.0.1 interim_fix004
Version 21.0.1 interim_fix005
Version 21.0.1 interim_fix006

References (4)

Source: psirt@us.ibm.com
VDB EntryVendor Advisory
Source: psirt@us.ibm.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
VDB EntryVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.