// For flags

CVE-2019-4552

 

Severity Score

6.1
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 are vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is clicked. This would allow the attacker to perform further attacks, such as Web cache poisoning, cross-site scripting, and possibly obtain sensitive information. IBM X-Force ID: 165960.

IBM Security Access Manager versión 9.0.7 e IBM Security Verify Access versión 10.0.0, son vulnerables a unos ataques de división de respuesta HTTP. Un atacante remoto podría explotar esta vulnerabilidad usando una URL especialmente diseñada y causar que el servidor devuelva una respuesta dividida, una vez que se hace clic en la URL. Esto permitiría al atacante llevar a cabo más ataques, como un envenenamiento de la caché web, un cross-site scripting y posiblemente obtener información confidencial.  IBM X-Force ID: 165960

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2019-01-03 CVE Reserved
  • 2020-10-15 CVE Published
  • 2023-10-19 EPSS Updated
  • 2024-09-16 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Ibm
Search vendor "Ibm"
Security Access Manager
Search vendor "Ibm" for product "Security Access Manager"
>= 9.0.7.0 < 9.0.7.2
Search vendor "Ibm" for product "Security Access Manager" and version " >= 9.0.7.0 < 9.0.7.2"
-
Affected
Ibm
Search vendor "Ibm"
Security Verify Access
Search vendor "Ibm" for product "Security Verify Access"
>= 10.0.0 < 10.0.0.1
Search vendor "Ibm" for product "Security Verify Access" and version " >= 10.0.0 < 10.0.0.1"
-
Affected