CVE-2019-4461: IBM Cloud Orchestrator
Medium severity, CVSS 5.4. EPSS: 0.6% chance of exploitation in the next 30 days.
IBM Cloud Orchestrator 2.4 through 2.4.0.5 and 2.5 through 2.5.0.9 is vulnerable to HTTP Response Splitting caused by improper caching of content. This would allow the attacker to perform further attacks, such as Web Cache poisoning, cross-site scripting and possibly obtain sensitive information. IBM X-Force ID: 163682.
Affected products
- IBM Cloud Orchestrator: from 2.4.0.0, up to and including 2.4.0.5; from 2.5.0.0, up to and including 2.5.0.9
Published 2019-10-25. Last modified 2026-06-17.