← Vulnerability feed

Vulnerability record · CVE-2023-45190 · published 9 February 2024

CVE-2023-45190: Ibm engineering lifecycle optimization improper restriction of authentication attempts vulnerability

Ibm · Engineering Lifecycle Optimization

IBM Engineering Lifecycle Optimization 7.0.2 and 7.0.3 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 268754.

6.1 CVSS 3.1 Medium EPSS 0.26% · top 84.7% CWE-307 · Improper restriction of authentication attemptsCWE-644 · CWE-644
6.1CVSS 3.1 base score
0.26%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

IBM Engineering Lifecycle Optimization 7.0.2 and 7.0.3 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 268754.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-45190 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2023-45187Ibm engineering lifecycle optimization insufficient session expiration vulnerabilityIBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 does not invalidate session after logout which could allow an authenticated user …EPSS 0.38%8.8CVE-2021-29844Ibm engineering lifecycle optimization server-side request forgery (ssrf) vulnerabilityIBM Jazz Team Server products is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requ…EPSS 0.59%7.5CVE-2023-45191Ibm engineering lifecycle optimization improper restriction of authentication attempts vulnerabilityIBM Engineering Lifecycle Optimization 7.0.2 and 7.0.3 uses an inadequate account lockout setting that could allow a remote attacker to brute force a…EPSS 0.66%7.5CVE-2021-29774Ibm engineering lifecycle optimization vulnerabilityIBM Jazz Team Server products could allow an authenticated user to obtain elevated privileges under certain configurations. IBM X-Force ID: 203025.EPSS 0.98%6.5CVE-2021-29786Ibm engineering lifecycle optimization cleartext storage of sensitive data vulnerabilityIBM Jazz Team Server products stores user credentials in clear text which can be read by an authenticated user. IBM X-Force ID: 203172.EPSS 0.56%6.1CVE-2024-52890Ibm engineering lifecycle optimization vulnerabilityIBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.03 could be susceptible to cross-site scripting due to no validation of URIs.EPSS 0.18%5.4CVE-2021-29673Ibm engineering lifecycle optimization cross-site scripting vulnerabilityIBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web U…EPSS 0.50%5.4CVE-2021-29713Ibm engineering lifecycle optimization cross-site scripting vulnerabilityIBM Jazz Team Server products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web U…EPSS 0.50%

Source: NIST National Vulnerability Database (record CVE-2023-45190), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.