peter bassill · operator
$ cve CVE-2016-0400 JSON

CVE-2016-0400 EXPLOIT

6.1
MEDIUM · CVSS 3.0 · EPSS 2.1% (pctl 81)

Patch early

A public exploit exists.

Description

CRLF injection vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3, 7.1.1 before 7.1.1.1, 8.5 before 8.5.0.3, and 8.6 before 8.6.0.8 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL.

Scoring

CVSS6.1 (MEDIUM, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS2.14% — more likely to be exploited than 81% of all CVEs
On CISA KEVno
Public exploityes
Published2016-07-02
Last modified2026-06-17

Affected (1)

VendorProduct
ibmwebsphere extreme scale

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD