VDB
CVE-2024-1135
CVE-2024-1135
PUBLISHED
CVSS 9.300000190734863 CRITICAL
Es existiert eine Schwachstelle in IBM Business Automation Workflow Machine Learning Server. Dieser Fehler betrifft die Gunicorn-Komponente aufgrund der unsachgemäßen Analyse der HTTP-Transfer-Encoding-Header, was zum Schmuggeln von HTTP-Anfragen führt. Ein entfernter, anonymer Angreifer kann diese Schwachstelle ausnutzen, um die Interpretation von HTTP-Anfragen zu manipulieren, was zu Web-Cache-Poisoning, zur Umgehung des Webanwendungsschutzes und zu XSS-Angriffen führen kann.
EPSS 0.09% · 24.7th percentile
Risk Scores
CVSS 4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
EPSS Score
0.09%
24.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oracle | Oracle Communications 25.1.101 | |
| Oracle | Oracle Communications <=9.0.4 | |
| Oracle | Oracle Communications 9.2.0 | |
| Amazon | Amazon Linux 2 | |
| Oracle | Oracle Communications 15.0.1 | |
| Dell | Dell PowerProtect Data Domain <8.3.1.10 | |
| Oracle | Oracle Communications 15.0.0 | |
| Oracle | Oracle Communications 5.2 | |
| Oracle | Oracle Communications 9.1.1.9 | |
| Red Hat | Red Hat Enterprise Linux | |
| Oracle | Oracle Communications 24.1.0 | |
| Oracle | Oracle Communications 24.3.0 | |
| SUSE | SUSE Linux | |
| Oracle | Oracle Communications 14.0.0 | |
| Red Hat | Red Hat OpenStack 16.2 | |
| Red Hat | Red Hat Satellite 6.15 | |
| Dell | Dell PowerProtect Data Domain <7.10.1.70 | |
| Dell | Dell PowerProtect Data Domain <7.13.1.40 | |
| Oracle | Oracle Communications 9.1.5 | |
| Oracle | Oracle Communications 9.0.1 |
…and 43 more
Exploit Intelligence
- A poc for Bootstrap XSS(CVE-2024-6485、CVE-2016-10735、CVE-2019-8331、CVE-2018-14040) (github-poc)
- A poc for Bootstrap XSS(CVE-2024-6485、CVE-2016-10735、CVE-2019-8331、CVE-2018-14040) (github-poc)
- A poc for Bootstrap XSS(CVE-2024-6485、CVE-2016-10735、CVE-2019-8331、CVE-2018-14040) (github-poc)
- A poc for Bootstrap XSS(CVE-2024-6485、CVE-2016-10735、CVE-2019-8331、CVE-2018-14040) (github-poc)
- A poc for Bootstrap XSS(CVE-2024-6485、CVE-2016-10735、CVE-2019-8331、CVE-2018-14040) (github-poc)
- A poc for Bootstrap XSS(CVE-2024-6485、CVE-2016-10735、CVE-2019-8331、CVE-2018-14040) (github-poc)
- A poc for Bootstrap XSS(CVE-2024-6485、CVE-2016-10735、CVE-2019-8331、CVE-2018-14040) (github-poc)
- A poc for Bootstrap XSS(CVE-2024-6485、CVE-2016-10735、CVE-2019-8331、CVE-2018-14040) (github-poc)
- A poc for Bootstrap XSS(CVE-2024-6485、CVE-2016-10735、CVE-2019-8331、CVE-2018-14040) (github-poc)
- A poc for Bootstrap XSS(CVE-2024-6485、CVE-2016-10735、CVE-2019-8331、CVE-2018-14040) (github-poc)
…and 60 more exploits
Timeline
- CVE Published
- Apr 16, 2024 EPSS Score
- May 11, 2024 EPSS Score
- Jun 6, 2024 EPSS Score
- Jun 30, 2024 EPSS Score
- Jul 25, 2024 EPSS Score
- Aug 23, 2024 EPSS Score
- Sep 17, 2024 EPSS Score
- Oct 4, 2024 Coalition ESS Score
- Oct 11, 2024 EPSS Score
- Nov 5, 2024 EPSS Score
- Nov 30, 2024 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2024/wid-sec-w-2024-1228.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2024-1228 advisory
- https://access.redhat.com/errata/RHSA-2024:2727 advisory
- https://access.redhat.com/errata/RHSA-2024:2729 advisory
- https://access.redhat.com/errata/RHSA-2024:2730 advisory
- https://access.redhat.com/errata/RHSA-2024:2767 advisory
- https://access.redhat.com/errata/RHSA-2024:2731 advisory
- https://access.redhat.com/errata/RHSA-2024:2732 advisory
- https://access.redhat.com/errata/RHSA-2024:2733 advisory
- https://access.redhat.com/errata/RHSA-2024:2734 advisory
- https://access.redhat.com/errata/RHSA-2024:2735 advisory
- https://access.redhat.com/errata/RHSA-2024:2768 advisory
- https://access.redhat.com/errata/RHSA-2024:2736 advisory
- https://access.redhat.com/errata/RHSA-2024:2770 advisory
- https://access.redhat.com/errata/RHSA-2024:2737 advisory
- https://access.redhat.com/errata/RHSA-2024:2769 advisory
- https://access.redhat.com/errata/RHSA-2024:3352 advisory
- https://access.redhat.com/errata/RHSA-2024:3327 advisory
- https://access.redhat.com/errata/RHSA-2024:3331 advisory
- https://access.redhat.com/errata/RHSA-2024:3467 advisory
…and 66 more