IBM i 7.3, 7.4, 7.5, and 7.5 is vulnerable to a host header injection attack caused by improper neutralization of HTTP header content by IBM Navigator for i. An authenticated user can manipulate the host header in HTTP requests to change domain/IP address which may lead to unexpected behavior.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.ibm.com/support/pages/node/7231320 |
![]() ![]() |
History
Fri, 18 Apr 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 18 Apr 2025 15:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | IBM i 7.3, 7.4, 7.5, and 7.5 is vulnerable to a host header injection attack caused by improper neutralization of HTTP header content by IBM Navigator for i. An authenticated user can manipulate the host header in HTTP requests to change domain/IP address which may lead to unexpected behavior. | |
Title | IBM i improper HTTP header neutralization | |
First Time appeared |
Ibm
Ibm i |
|
Weaknesses | CWE-644 | |
CPEs | cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:* cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:* cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:* cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:* |
|
Vendors & Products |
Ibm
Ibm i |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: ibm
Published: 2025-04-18T14:50:21.165Z
Updated: 2025-04-18T15:08:43.627Z
Reserved: 2025-03-29T16:56:59.875Z
Link: CVE-2025-2950

Updated: 2025-04-18T15:05:13.386Z

Status : Awaiting Analysis
Published: 2025-04-18T15:15:58.937
Modified: 2025-04-21T14:23:45.950
Link: CVE-2025-2950

No data.