CVE-2022-34362
4.6
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Exploitability: 2.1 / Impact: 2.5
Source: NVD
Description
IBM Sterling Secure Proxy 6.0.3 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 230523.
Affected (1)
Products: Ibm: Sterling Secure Proxy
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6.0.3 |
| Running on/with | Platform Versions |
|---|---|
Ibm Aix | All versions |
Ibm Linux On Ibm Z | All versions |
Linux Linux Kernel | All versions |
Microsoft Windows | All versions |
References (4)
Source: psirt@us.ibm.com
VDB EntryVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
VDB EntryVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Timeline
No history available yet.