Description
IBM Security Access Manager 9.0.7 and IBM Security Verify Access 10.0.0 are vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is clicked. This would allow the attacker to perform further attacks, such as Web cache poisoning, cross-site scripting, and possibly obtain sensitive information. IBM X-Force ID: 165960.
Remediation
References
Related Vulnerabilities
Microsoft SQL Server Other Vulnerability (CVE-2000-1082)
WordPress Plugin uContext for Clickbank Cross-Site Request Forgery (3.9.1)
PHP Other Vulnerability (CVE-2007-1401)
Apache HTTP Server Improper Access Control Vulnerability (CVE-2016-4979)
WordPress Plugin Hunk External Links Cross-Site Scripting (3.0.5)