Vulnerability Details CVE-2016-0359
CRLF injection vulnerability in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.43, 8.0 before 8.0.0.13, 8.5 Full before 8.5.5.10, and 8.5 Liberty before Liberty Fix Pack 16.0.0.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 54.7%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 4.3
Products affected by CVE-2016-0359
-
cpe:2.3:a:ibm:websphere_application_server:7.0
-
cpe:2.3:a:ibm:websphere_application_server:7.0.0.0
-
cpe:2.3:a:ibm:websphere_application_server:7.0.0.1
-
cpe:2.3:a:ibm:websphere_application_server:7.0.0.10
-
cpe:2.3:a:ibm:websphere_application_server:7.0.0.11
-
cpe:2.3:a:ibm:websphere_application_server:7.0.0.12
-
cpe:2.3:a:ibm:websphere_application_server:7.0.0.13
-
cpe:2.3:a:ibm:websphere_application_server:7.0.0.14
-
cpe:2.3:a:ibm:websphere_application_server:7.0.0.15
-
cpe:2.3:a:ibm:websphere_application_server:7.0.0.16
-
cpe:2.3:a:ibm:websphere_application_server:7.0.0.17
-
cpe:2.3:a:ibm:websphere_application_server:7.0.0.18
-
cpe:2.3:a:ibm:websphere_application_server:7.0.0.19
-
cpe:2.3:a:ibm:websphere_application_server:7.0.0.2
-
cpe:2.3:a:ibm:websphere_application_server:7.0.0.21
-
cpe:2.3:a:ibm:websphere_application_server:7.0.0.22
-
cpe:2.3:a:ibm:websphere_application_server:7.0.0.23
-
cpe:2.3:a:ibm:websphere_application_server:7.0.0.24
-
cpe:2.3:a:ibm:websphere_application_server:7.0.0.25
-
cpe:2.3:a:ibm:websphere_application_server:7.0.0.27
-
cpe:2.3:a:ibm:websphere_application_server:7.0.0.28
-
cpe:2.3:a:ibm:websphere_application_server:7.0.0.29
-
cpe:2.3:a:ibm:websphere_application_server:7.0.0.3
-
cpe:2.3:a:ibm:websphere_application_server:7.0.0.31
-
cpe:2.3:a:ibm:websphere_application_server:7.0.0.32
-
cpe:2.3:a:ibm:websphere_application_server:7.0.0.33
-
cpe:2.3:a:ibm:websphere_application_server:7.0.0.34
-
cpe:2.3:a:ibm:websphere_application_server:7.0.0.35
-
cpe:2.3:a:ibm:websphere_application_server:7.0.0.36
-
cpe:2.3:a:ibm:websphere_application_server:7.0.0.37
-
cpe:2.3:a:ibm:websphere_application_server:7.0.0.38
-
cpe:2.3:a:ibm:websphere_application_server:7.0.0.39
-
cpe:2.3:a:ibm:websphere_application_server:7.0.0.4
-
cpe:2.3:a:ibm:websphere_application_server:7.0.0.41
-
cpe:2.3:a:ibm:websphere_application_server:7.0.0.5
-
cpe:2.3:a:ibm:websphere_application_server:7.0.0.6
-
cpe:2.3:a:ibm:websphere_application_server:7.0.0.7
-
cpe:2.3:a:ibm:websphere_application_server:7.0.0.8
-
cpe:2.3:a:ibm:websphere_application_server:7.0.0.9
-
cpe:2.3:a:ibm:websphere_application_server:8.0
-
cpe:2.3:a:ibm:websphere_application_server:8.0.0.0
-
cpe:2.3:a:ibm:websphere_application_server:8.0.0.1
-
cpe:2.3:a:ibm:websphere_application_server:8.0.0.10
-
cpe:2.3:a:ibm:websphere_application_server:8.0.0.11
-
cpe:2.3:a:ibm:websphere_application_server:8.0.0.12
-
cpe:2.3:a:ibm:websphere_application_server:8.0.0.2
-
cpe:2.3:a:ibm:websphere_application_server:8.0.0.3
-
cpe:2.3:a:ibm:websphere_application_server:8.0.0.4
-
cpe:2.3:a:ibm:websphere_application_server:8.0.0.5
-
cpe:2.3:a:ibm:websphere_application_server:8.0.0.6
-
cpe:2.3:a:ibm:websphere_application_server:8.0.0.7
-
cpe:2.3:a:ibm:websphere_application_server:8.0.0.8
-
cpe:2.3:a:ibm:websphere_application_server:8.0.0.9
-
cpe:2.3:a:ibm:websphere_application_server:8.5.0.0
-
cpe:2.3:a:ibm:websphere_application_server:8.5.5.4
-
cpe:2.3:a:ibm:websphere_application_server:8.5.5.5
-
cpe:2.3:a:ibm:websphere_application_server:8.5.5.6
-
cpe:2.3:a:ibm:websphere_application_server:8.5.5.7
-
cpe:2.3:a:ibm:websphere_application_server:8.5.5.8
-
cpe:2.3:a:ibm:websphere_application_server:8.5.5.9