216.73.216.6

CVE-2025-2950

· Published 18/04/2025 15:15 · Modified 18/04/2025 15:15

Labels: CVE-2025-2950 2025-04-18CVE-2025-2950CWE-644[email protected]

Essential information

Published
18/04/2025 15:15
Modified
18/04/2025 15:15
Author
Creator
CVSS
5.4 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

CVSS metrics

Description

IBM i 7.3, 7.4, 7.5, and 7.5 is vulnerable to a host header injection attack caused by improper neutralization of HTTP header content by IBM Navigator for i. An authenticated user can manipulate the host header in HTTP requests to change domain/IP address which may lead to unexpected behavior.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
ibm / ibm i cpe:2.3:a:ibm:ibm_i:7.3:*:*:*:*:*:*:*
ibm / ibm i cpe:2.3:a:ibm:ibm_i:7.4:*:*:*:*:*:*:*
ibm / ibm i cpe:2.3:a:ibm:ibm_i:7.5:*:*:*:*:*:*:*

References