CVE Published: 05/09/2019 |
CVE Updated: 16/09/2024 |
CVE Year: 2019 Source: ibm |
Vendor: IBM |
Product: Jazz for Service Management Status : PUBLISHED
CVE-2019-4186 Description
IBM Jazz for Service Management 1.1.3 is vulnerable to HTTP header injection, caused by incorrect trust in the HTTP Host header during caching. By sending a specially crafted HTTP GET request, a remote attacker could exploit this vulnerability to inject arbitrary HTTP headers, which will allow the attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-force ID: 158976.