Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8c8c-3855-2gv4

Опубликовано: 21 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

IBM i 7.3, 7.4, 7.5, and 7.5 is vulnerable to a host header injection attack caused by improper neutralization of HTTP header content by IBM Navigator for i. An authenticated user can manipulate the host header in HTTP requests to change domain/IP address which may lead to unexpected behavior.

IBM i 7.3, 7.4, 7.5, and 7.5 is vulnerable to a host header injection attack caused by improper neutralization of HTTP header content by IBM Navigator for i. An authenticated user can manipulate the host header in HTTP requests to change domain/IP address which may lead to unexpected behavior.

EPSS

Процентиль: 18%
0.00056
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-644

Связанные уязвимости

CVSS3: 5.4
nvd
10 месяцев назад

IBM i 7.3, 7.4, 7.5, and 7.5 is vulnerable to a host header injection attack caused by improper neutralization of HTTP header content by IBM Navigator for i. An authenticated user can manipulate the host header in HTTP requests to change domain/IP address which may lead to unexpected behavior.

CVSS3: 5.4
fstec
10 месяцев назад

Уязвимость операционной системы IBM i, связанная с недостатками обработки HTTP-запросов, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 18%
0.00056
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-644