IBM i 7.3, 7.4, 7.5, and 7.5 is vulnerable to a host header injection attack caused by improper neutralization of HTTP header content by IBM Navigator for i. An authenticated user can manipulate the host header in HTTP requests to change domain/IP address which may lead to unexpected behavior.
History

Fri, 18 Apr 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Apr 2025 15:00:00 +0000

Type Values Removed Values Added
Description IBM i 7.3, 7.4, 7.5, and 7.5 is vulnerable to a host header injection attack caused by improper neutralization of HTTP header content by IBM Navigator for i. An authenticated user can manipulate the host header in HTTP requests to change domain/IP address which may lead to unexpected behavior.
Title IBM i improper HTTP header neutralization
First Time appeared Ibm
Ibm i
Weaknesses CWE-644
CPEs cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published: 2025-04-18T14:50:21.165Z

Updated: 2025-04-18T15:08:43.627Z

Reserved: 2025-03-29T16:56:59.875Z

Link: CVE-2025-2950

cve-icon Vulnrichment

Updated: 2025-04-18T15:05:13.386Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-18T15:15:58.937

Modified: 2025-04-21T14:23:45.950

Link: CVE-2025-2950

cve-icon Redhat

No data.