CVE-2014-3021
N/A
N/A
Summary
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.35, 8.0 before 8.0.0.10, and 8.5 before 8.5.5.4 does not properly handle HTTP headers, which allows remote attackers to obtain sensitive cookie and authentication data via an unspecified HTTP method.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://www-01.ibm.com/support/docview.wss?uid=swg1PI08268
- http://www-01.ibm.com/support/docview.wss?uid=swg21684612
- https://exchange.xforce.ibmcloud.com/vulnerabilities/93059
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1PI08268
- http://www-01.ibm.com/support/docview.wss?uid=swg21684612
- https://exchange.xforce.ibmcloud.com/vulnerabilities/93059
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.