First published: Fri Mar 11 2022(Updated: )
IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 220038
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Storage Copy Data Management | <=2.2.0.0-2.2.14.3 | |
IBM Storage Copy Data Management | >=2.2.0.0<2.2.15.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2022-22344.
The affected software is IBM Spectrum Copy Data Management version 2.2.0.0 through 2.2.14.3.
The severity of CVE-2022-22344 is medium.
The possible attacks that can be conducted with this vulnerability include cross-site scripting, cache poisoning, or session hijacking.
Yes, IBM has released a fix for this vulnerability. Please refer to the IBM support page for more details.