漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
IBM Jazz for Service Management 1.1.3 is vulnerable to HTTP header injection, caused by incorrect trust in the HTTP Host header during caching. By sending a specially crafted HTTP GET request, a remote attacker could exploit this vulnerability to inject arbitrary HTTP headers, which will allow the attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-force ID: 158976.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
IBM Jazz for Service Management 跨站脚本漏洞
Vulnerability Description
IBM Jazz for Service Management是美国国际商业机器(IBM)公司的一款提供对服务管理环境可见性的集成服务管理产品。 IBM Jazz for Service Management 1.1.3版本中存在跨站脚本漏洞。攻击者可通过发送特制的HTTP GET请求利用该漏洞注入任意的HTTP头,进而实施攻击,例如:跨站脚本、缓存中毒或会话劫持。
CVSS Information
N/A
Vulnerability Type
N/A