CVE Database
/

CVE-2017-1503

Back to search

CVE-2017-1503

Published: Oct 10, 2017

Modified: Aug 5, 2024

PUBLISHED

Description

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is clicked. This would allow the attacker to perform further attacks, such as Web cache poisoning, cross-site scripting, and possibly obtain sensitive information. IBM X-Force ID: 129578.

VendorProductVersions

IBM

IBM WebSphere Application Server

affected
7.0, 8.0, 8.5, 9.0

References

101234
vdb-entry
x_refsource_BID
1039521
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now