AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2014-3021

MEDIUM · CVSS 5 EPSS 2.23%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2014-10-19 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2014-3021
Severity
MEDIUM
CVSS
5
EPSS
2.23%

Original NVD Description

IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.35, 8.0 before 8.0.0.10, and 8.5 before 8.5.5.4 does not properly handle HTTP headers, which allows remote attackers to obtain sensitive cookie and authentication data via an unspecified HTTP method.