CVE-2015-2028

IBM WebSphere eXtreme Scale <7.1.0.3, <7.1.1 - CRLF Injection

Title source: llm
STIX 2.1

Description

CRLF injection vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL.

References (3)

Core 3
Core References
Patch, Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21966044
Patch, Vendor Advisory vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1PI44105
Patch, Vendor Advisory vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1PI44098

Scores

EPSS 0.0120
EPSS Percentile 65.1%

Details

Status published
Products (3)
ibm/websphere_extreme_scale 7.1.0
ibm/websphere_extreme_scale 7.1.0.2
ibm/websphere_extreme_scale 7.1.1
Published Oct 04, 2015
Tracked Since Feb 18, 2026