Reverse Tabnabbing Vulnerability in IBM Spectrum Protect Operations Center
CVE-2022-22348

4MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
14 March 2022

Summary

IBM Spectrum Protect Operations Center versions 8.1.0.000 through 8.1.13.xxx contain a vulnerability that facilitates reverse tabnabbing. This issue allows an attacker to exploit a malicious link entered by an administrator, leading to the overwriting of the original page with a fraudulent phishing page. As a result, unsuspecting users who click the link could be manipulated into revealing sensitive information. The potential risks underscore the importance of safeguarding against improper validation of external links.

Affected Version(s)

Spectrum Protect Operations Center 8.1.0.000

Spectrum Protect Operations Center 8.1.13

References

CVSS V3.1

Score:
4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.