HTTP Header Injection Vulnerability in IBM Spectrum Copy Data Management
CVE-2022-22344
4.8MEDIUM
Summary
IBM Spectrum Copy Data Management versions 2.2.0.0 through 2.2.14.3 are susceptible to an HTTP header injection vulnerability. This security flaw arises from the inadequate validation of input provided in the HOST headers. Attackers may exploit this weakness to launch a range of attacks such as cross-site scripting, cache poisoning, or session hijacking, compromising the integrity and confidentiality of the affected systems. Organizations using the vulnerable versions should implement timely updates or security measures to mitigate the risks associated with this vulnerability.
Affected Version(s)
Spectrum Copy Data Management 2.2.0.0
Spectrum Copy Data Management 2.2.14.3
References
CVSS V3.1
Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved