HTTP response splitting in Microsoft products - CVE-2020-0645
Published: March 10, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform HTTP splitting attacks.
The vulnerability exists due to software does not corrector process HTTP request headers. A remote attacker can send specially crafted HTTP request and modify the response, sent by the web server.
Successful exploitation of the vulnerability may allow an attacker perform cache poisoning attack.
Affected software
Windows Server
Microsoft Internet Information Services (IIS)
Solutions Enabler Virtual Appliance
Solutions Enabler
Unisphere for PowerMax Virtual Appliance
Unisphere for PowerMax
How to mitigate CVE-2020-0645
Solutions Enabler - addressed in versions 9.0.0.19, 9.1.0.6
Unisphere for PowerMax Virtual Appliance - addressed in versions 9.0.2.18, 9.1.0.17
Unisphere for PowerMax - addressed in versions 9.0.2.18, 9.1.0.17