CVE-2010-0155
IBM Proventia Network Mail Security System Authenticated HTTP Response Splitting via javaVersion Parameter
Title source: llmDescription
CRLF injection vulnerability in load.php in the Local Management Interface (LMI) on the IBM Proventia Network Mail Security System (PNMSS) appliance with firmware before 2.5 allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the javaVersion parameter.
References (2)
Core 2
Core References
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/513636/100/0/threaded
Various Sources x_refsource_misc
http://www.ventuneac.net/security-advisories/MVSA-10-009
Scores
EPSS
0.0070
EPSS Percentile
48.6%
Details
CWE
CWE-94
Status
published
Products (2)
ibm/proventia_network_mail_security_system_virtual_appliance
ibm/proventia_network_mail_security_system_virtual_appliance_firmware
1.6
Published
Sep 14, 2010
Tracked Since
Feb 18, 2026