CVE-2022-22348: CSRF
IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.13.xxx is vulnerable to reverse tabnabbing where it could allow a page linked to from within Operations Center to rewrite it. An administrator could enter a link to a malicious URL that another administrator could then click. Once clicked, that malicious URL could then rewrite the original page with a phishing page. IBM X-Force ID: 220139.
Other sources
IBM Spectrum Protect Operations Center is vulnerable to reverse tabnabbing where it could allow a page linked to from within Operations Center to rewrite it. An administrator could enter a link to a malicious URL that another administrator could then click. Once clicked, that malicious URL could then rewrite the original page with a phishing page.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-22348?
CVE-2022-22348 is a vulnerability in IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.13.xxx that allows a page linked to from within Operations Center to rewrite it, potentially leading to unauthorized actions.
How severe is CVE-2022-22348?
CVE-2022-22348 has a severity level of medium.
How does CVE-2022-22348 affect IBM Spectrum Protect Operations Center?
IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.13.xxx is affected by CVE-2022-22348.
What is reverse tabnabbing?
Reverse tabnabbing is a technique where a page linked to from within an application can rewrite it, potentially tricking users into performing unintended actions.
How can I protect my IBM Spectrum Protect Operations Center from CVE-2022-22348?
To protect against CVE-2022-22348, ensure that you only click links within Operations Center that are from trusted sources.