CVE-2007-1608
published 2007-03-22CVE-2007-1608: CRLF injection vulnerability in IBM WebSphere Application Server (WAS) before 6.0.2.19 allows remote attackers to inject arbitrary HTTP headers and conduct…
high7.5CVSS 3.1
AVNACLAuNCPIPAP
CRLF injection vulnerability in IBM WebSphere Application Server (WAS) before 6.0.2.19 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a single CRLF sequence in a context that is not a valid multi-line header.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | websphere_application_server | <= 6.0.2.15 | — |
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/34484http://secunia.com/advisories/24552http://www-1.ibm.com/support/docview.wss?uid=swg1PK39732http://www.securityfocus.com/bid/23086http://www.securitytracker.com/id?1017806http://www.vupen.com/english/advisories/2007/1062https://exchange.xforce.ibmcloud.com/vulnerabilities/33123http://osvdb.org/34484http://secunia.com/advisories/24552http://www-1.ibm.com/support/docview.wss?uid=swg1PK39732http://www.securityfocus.com/bid/23086http://www.securitytracker.com/id?1017806http://www.vupen.com/english/advisories/2007/1062https://exchange.xforce.ibmcloud.com/vulnerabilities/33123
2007-03-22
Published