First published: Fri Mar 11 2022(Updated: )
IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.13.xxx is vulnerable to reverse tabnabbing where it could allow a page linked to from within Operations Center to rewrite it. An administrator could enter a link to a malicious URL that another administrator could then click. Once clicked, that malicious URL could then rewrite the original page with a phishing page. IBM X-Force ID: 220139.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Spectrum Protect Operations Center | >=8.1.0.000<8.1.14.000 | |
<=8.1.0.000-8.1.13.xxx |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-22348 is a vulnerability in IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.13.xxx that allows a page linked to from within Operations Center to rewrite it, potentially leading to unauthorized actions.
CVE-2022-22348 has a severity level of medium.
IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.13.xxx is affected by CVE-2022-22348.
Reverse tabnabbing is a technique where a page linked to from within an application can rewrite it, potentially tricking users into performing unintended actions.
To protect against CVE-2022-22348, ensure that you only click links within Operations Center that are from trusted sources.