CVE-2022-22399: IBM Aspera Faspex HTTP header injection
IBM Aspera Faspex 5 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking.
Other sources
IBM Aspera Faspex 5.0.0 and 5.0.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 222562.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-22399?
The severity of CVE-2022-22399 is considered high due to its potential for allowing serious attacks such as cross-site scripting and session hijacking.
How do I fix CVE-2022-22399?
To fix CVE-2022-22399, update IBM Aspera Faspex to the latest version available which addresses the HTTP header injection vulnerability.
What systems are affected by CVE-2022-22399?
CVE-2022-22399 affects IBM Aspera Faspex versions 5.0.0 and 5.0.1.
What type of attacks can CVE-2022-22399 facilitate?
CVE-2022-22399 can facilitate attacks such as cross-site scripting, cache poisoning, and session hijacking.
Is authentication required to exploit CVE-2022-22399?
No, CVE-2022-22399 can potentially be exploited without authentication, making it more dangerous.