CVE-2007-1608

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/03/2007
Last modified:
09/04/2025

Description

CRLF injection vulnerability in IBM WebSphere Application Server (WAS) before 6.0.2.19 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a single CRLF sequence in a context that is not a valid multi-line header.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ibm:websphere_application_server:*:*:*:*:*:*:*:* 6.0.2.15 (including)