CVE-2010-0155

IBM Proventia Network Mail Security System Authenticated HTTP Response Splitting via javaVersion Parameter

Title source: llm
STIX 2.1

Description

CRLF injection vulnerability in load.php in the Local Management Interface (LMI) on the IBM Proventia Network Mail Security System (PNMSS) appliance with firmware before 2.5 allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the javaVersion parameter.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/513636/100/0/threaded

Scores

EPSS 0.0070
EPSS Percentile 48.6%

Details

CWE
CWE-94
Status published
Products (2)
ibm/proventia_network_mail_security_system_virtual_appliance
ibm/proventia_network_mail_security_system_virtual_appliance_firmware 1.6
Published Sep 14, 2010
Tracked Since Feb 18, 2026