CVE-2014-3021

EUVD-2014-3042
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.35, 8.0 before 8.0.0.10, and 8.5 before 8.5.5.4 does not properly handle HTTP headers, which allows remote attackers to obtain sensitive cookie and authentication data via an unspecified HTTP method.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 52%
Affected Products (NVD)
VendorProductVersion
ibmwebsphere_application_server
7.0
ibmwebsphere_application_server
7.0.0.1
ibmwebsphere_application_server
7.0.0.2
ibmwebsphere_application_server
7.0.0.3
ibmwebsphere_application_server
7.0.0.4
ibmwebsphere_application_server
7.0.0.5
ibmwebsphere_application_server
7.0.0.6
ibmwebsphere_application_server
7.0.0.7
ibmwebsphere_application_server
7.0.0.8
ibmwebsphere_application_server
7.0.0.9
ibmwebsphere_application_server
7.0.0.10
ibmwebsphere_application_server
7.0.0.11
ibmwebsphere_application_server
7.0.0.12
ibmwebsphere_application_server
7.0.0.13
ibmwebsphere_application_server
7.0.0.14
ibmwebsphere_application_server
7.0.0.15
ibmwebsphere_application_server
7.0.0.16
ibmwebsphere_application_server
7.0.0.17
ibmwebsphere_application_server
7.0.0.18
ibmwebsphere_application_server
7.0.0.19
ibmwebsphere_application_server
7.0.0.21
ibmwebsphere_application_server
7.0.0.22
ibmwebsphere_application_server
7.0.0.23
ibmwebsphere_application_server
7.0.0.24
ibmwebsphere_application_server
7.0.0.25
ibmwebsphere_application_server
7.0.0.27
ibmwebsphere_application_server
7.0.0.28
ibmwebsphere_application_server
7.0.0.29
ibmwebsphere_application_server
7.0.0.31
ibmwebsphere_application_server
7.0.0.32
ibmwebsphere_application_server
7.0.0.33
ibmwebsphere_application_server
7.0.0.34
ibmwebsphere_application_server
8.0
ibmwebsphere_application_server
8.0.0.0
ibmwebsphere_application_server
8.0.0.1
ibmwebsphere_application_server
8.0.0.2
ibmwebsphere_application_server
8.0.0.3
ibmwebsphere_application_server
8.0.0.4
ibmwebsphere_application_server
8.0.0.5
ibmwebsphere_application_server
8.0.0.6
ibmwebsphere_application_server
8.0.0.7
ibmwebsphere_application_server
8.0.0.8
ibmwebsphere_application_server
8.0.0.9
ibmwebsphere_application_server
8.5.0.0
ibmwebsphere_application_server
8.5.0.0
ibmwebsphere_application_server
8.5.0.1
ibmwebsphere_application_server
8.5.0.1
ibmwebsphere_application_server
8.5.0.2
ibmwebsphere_application_server
8.5.0.2
ibmwebsphere_application_server
8.5.5.0
ibmwebsphere_application_server
8.5.5.0
ibmwebsphere_application_server
8.5.5.1
ibmwebsphere_application_server
8.5.5.1
ibmwebsphere_application_server
8.5.5.2
ibmwebsphere_application_server
8.5.5.2
ibmwebsphere_application_server
8.5.5.3
ibmwebsphere_application_server
8.5.5.3
𝑥
= Vulnerable software versions