CVE-2019-4552: Medium severity IBM ISAM vulnerability
IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 are vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is clicked. This would allow the attacker to perform further attacks, such as Web cache poisoning, cross-site scripting, and possibly obtain sensitive information. IBM X-Force ID: 165960.
Other sources
IBM Security Access Manager Appliance is vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is clicked. This would allow the attacker to perform further attacks, such as Web cache poisoning, cross-site scripting, and possibly obtain sensitive information.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2019-4552.
What is the severity of CVE-2019-4552?
The severity of CVE-2019-4552 is medium with a severity value of 6.1.
Which products are affected by CVE-2019-4552?
IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 are affected by CVE-2019-4552.
What is the risk posed by CVE-2019-4552?
CVE-2019-4552 poses the risk of HTTP response splitting attacks.
How can CVE-2019-4552 be exploited?
CVE-2019-4552 can be exploited by a remote attacker using a specially-crafted URL to cause the server to return a split response.