CVE-2018-1474 describes an HTTP response splitting vulnerability in IBM BigFix Platform versions 9.2.0 through 9.2.14 and 9.5 through 9.5.9, stemming from improper validation of user-supplied input. An attacker could exploit this by injecting arbitrary HTTP headers to cause a split response, leading to further attacks like web cache poisoning or cross-site scripting, and potential information disclosure. The vulnerability has a CVSS v3 score of 4.7 (Medium), indicating a network-based attack requiring user interaction, with low impact on integrity and no impact on confidentiality or availability. Its EPSS score is very low, suggesting a minimal likelihood of exploitation. There is no evidence of active exploitation, no public exploit code available (Metasploit, Nuclei, ExploitDB), and it has garnered no community discussion or media coverage, indicating a low level of attention and perceived threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.2.0, <= 9.2.14CPE matchmatch criteria | cpe:2.3:a:ibm:bigfix_platform:*:*:*:*:*:*:*:* | ||
>= 9.5, <= 9.5.9CPE matchmatch criteria | cpe:2.3:a:ibm:bigfix_platform:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.