PT-2024-4958 · Ibm · Ibm Datacap Navigator

CVE-2024-39736

·

Published

2024-07-12

·

Updated

2024-07-16

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: IBM Datacap Navigator versions 9.1.5 through 9.1.9
Description: The issue is related to improper validation of input by the HOST headers in HTTP requests, which could allow a remote attacker to conduct various attacks, including cross-site scripting, cache poisoning, or session hijacking.
Recommendations: For versions 9.1.5 through 9.1.9, update to a version that properly validates input by the HOST headers to prevent HTTP header injection attacks. As a temporary workaround, consider restricting access to the vulnerable system to minimize the risk of exploitation.

Fix

Improper Encoding or Escaping of Output

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-05482
CVE-2024-39736

Affected Products

Ibm Datacap Navigator