CVE-2018-1943 is an HTTP Host header injection vulnerability affecting IBM Cloud Private versions 3.1.0 and 3.1.1, stemming from improper input validation. This medium-severity flaw (CVSS 5.4) could allow a remote attacker to inject arbitrary HTTP headers by tricking a user into visiting a malicious webpage, potentially leading to cross-site scripting, cache poisoning, or session hijacking. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.1.0CPE matchmatch criteria | cpe:2.3:a:ibm:cloud_private:3.1.0:*:*:*:*:*:*:* | ||
3.1.1CPE matchmatch criteria | cpe:2.3:a:ibm:cloud_private:3.1.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.