Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8c8c-3855-2gv4

Опубликовано: 21 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

IBM i 7.3, 7.4, 7.5, and 7.5 is vulnerable to a host header injection attack caused by improper neutralization of HTTP header content by IBM Navigator for i. An authenticated user can manipulate the host header in HTTP requests to change domain/IP address which may lead to unexpected behavior.

IBM i 7.3, 7.4, 7.5, and 7.5 is vulnerable to a host header injection attack caused by improper neutralization of HTTP header content by IBM Navigator for i. An authenticated user can manipulate the host header in HTTP requests to change domain/IP address which may lead to unexpected behavior.

EPSS

Процентиль: 22%
0.00298
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-644

Связанные уязвимости

CVSS3: 5.4
nvd
больше 1 года назад

IBM i 7.3, 7.4, 7.5, and 7.5 is vulnerable to a host header injection attack caused by improper neutralization of HTTP header content by IBM Navigator for i. An authenticated user can manipulate the host header in HTTP requests to change domain/IP address which may lead to unexpected behavior.

CVSS3: 5.4
fstec
больше 1 года назад

Уязвимость операционной системы IBM i, связанная с недостатками обработки HTTP-запросов, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 22%
0.00298
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-644