IBM SmartCloud Analytics - Log Analysis HOST header injection
Published Jul 23, 2025
6.1
MEDIUMCVSS 3.1
EPSS 0.18%
Description
IBM SmartCloud Analytics - Log Analysis 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, and 1.3.8.2 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking.
Affected products
-
- Version 1.3.7.0, 1.3.7.1, 1.3.7.2, 1.3.8.0, 1.3.8.1, 1.3.8.2StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| IBM | SmartCloud Analytics Log Analysis | unaffected |
|
- 1.3.7.0
- 1.3.7.1
- 1.3.7.2
- 1.3.8.0
- 1.3.8.1
- 1.3.8.2
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Apply Log Analysis version 1.3.8.2 Interim Fix 1. Download 1.3.8.2-TIV-IOALA-IF001. For Log Analysis before version 1.3.8.2, upgrade to 1.3.8-TIV-IOALA-FP2 before installing this fix.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-54813 Advisory
- https://www.ibm.com/support/pages/node/7240270 vendor-advisorypatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-54813 | Advisory | |
| https://www.ibm.com/support/pages/node/7240270 | vendor-advisorypatchVendor Advisory |
Change history (0)
No recorded changes yet.