Security Bulletin: IBM Operations Analytics – Log Analysis is vulnerable to potential Host Header Injection (CVE-2019-4216)

IBM Operations Analytics – Log Analysis is vulnerable to HTTP header injection, as attacker can abuse the HTTP Host header.

Affected product(s) and affected version(s):

Affected Product(s)Version(s)
Log Analysis1.3.1
Log Analysis1.3.2
Log Analysis1.3.3
Log Analysis1.3.4
Log Analysis1.3.5

Refer to the following reference URLs for remediation and additional vulnerability details:  
Source Bulletin: https://www.ibm.com/support/pages/node/1109745

The post Security Bulletin: IBM Operations Analytics – Log Analysis is vulnerable to potential Host Header Injection (CVE-2019-4216) appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team https://ift.tt/35mFEHu