CVE-2013-3998

IBM InfoSphere BigInsights 1.1 and 2.x < 2.1 FP2 - Authenticated CRLF Injection

Title source: llm
STIX 2.1

Description

CRLF injection vulnerability in the Web Application Enterprise Console in IBM InfoSphere BigInsights 1.1 and 2.x before 2.1 FP2 allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/84987
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21667812

Scores

EPSS 0.0077
EPSS Percentile 51.1%

Details

CWE
CWE-94
Status published
Products (10)
ibm/infosphere_biginsights 1.1.0.0
ibm/infosphere_biginsights 1.1.0.1
ibm/infosphere_biginsights 1.1.0.2
ibm/infosphere_biginsights 1.2.0.0
ibm/infosphere_biginsights 1.3.0.0
ibm/infosphere_biginsights 1.3.0.1
ibm/infosphere_biginsights 1.4.0.0
ibm/infosphere_biginsights 2.0.0.0
ibm/infosphere_biginsights 2.1.0.0
ibm/infosphere_biginsights 2.1.0.1
Published Mar 26, 2014
Tracked Since Feb 18, 2026