4.3
CVE-2015-2028
- EPSS 1.21%
- Veröffentlicht 04.10.2015 02:59:12
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Erkennungen
CRLF injection vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Websphere Extreme Scale Version 7.1.0
Ibm ≫ Websphere Extreme Scale Version 7.1.0.2
Ibm ≫ Websphere Extreme Scale Version 7.1.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.21% | 0.643 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
http://www-01.ibm.com/support/docview.wss?uid=swg1PI44098
http://www-01.ibm.com/support/docview.wss?uid=swg1PI44105
http://www-01.ibm.com/support/docview.wss?uid=swg21966044