CVE-2016-0400 EXPLOIT
6.1
MEDIUM · CVSS 3.0 · EPSS 2.1% (pctl 81)
Patch early
A public exploit exists.
Description
CRLF injection vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3, 7.1.1 before 7.1.1.1, 8.5 before 8.5.0.3, and 8.6 before 8.6.0.8 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL.
Scoring
| CVSS | 6.1 (MEDIUM, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
| EPSS | 2.14% — more likely to be exploited than 81% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2016-07-02 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| ibm | websphere extreme scale |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft Windows 7 SP1 (x86) - Local Privilege Escalation (MS16-014) | 2016-06-29 |
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1PI60897
- http://www-01.ibm.com/support/docview.wss?uid=swg1PI60898
- http://www-01.ibm.com/support/docview.wss?uid=swg21983036
- https://www.exploit-db.com/exploits/40039/
- http://www-01.ibm.com/support/docview.wss?uid=swg1PI60897
- http://www-01.ibm.com/support/docview.wss?uid=swg1PI60898
- http://www-01.ibm.com/support/docview.wss?uid=swg21983036
- https://www.exploit-db.com/exploits/40039/
→ the Explorer · watch your stack · NVD