HTTP Header Injection Vulnerability in IBM Spectrum Copy Data Management
CVE-2022-22344

4.8MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
14 March 2022

Summary

IBM Spectrum Copy Data Management versions 2.2.0.0 through 2.2.14.3 are susceptible to an HTTP header injection vulnerability. This security flaw arises from the inadequate validation of input provided in the HOST headers. Attackers may exploit this weakness to launch a range of attacks such as cross-site scripting, cache poisoning, or session hijacking, compromising the integrity and confidentiality of the affected systems. Organizations using the vulnerable versions should implement timely updates or security measures to mitigate the risks associated with this vulnerability.

Affected Version(s)

Spectrum Copy Data Management 2.2.0.0

Spectrum Copy Data Management 2.2.14.3

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.