First published: Tue Dec 13 2022(Updated: )
A vulnerability has been identified in Polarion ALM (All versions < V2304.0). The affected application contains a Host header injection vulnerability that could allow an attacker to spoof a Host header information and redirect users to malicious websites.
Credit: productcert@siemens.com productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Polarion ALM | <2304.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-46265 is considered a high severity vulnerability due to the risk of host header injection and potential redirection to malicious websites.
To fix CVE-2022-46265, update your Polarion ALM application to version 2304.0 or later to eliminate the host header injection vulnerability.
All versions of Polarion ALM prior to version 2304.0 are affected by CVE-2022-46265.
CVE-2022-46265 is a host header injection vulnerability that can allow attackers to spoof host information.
The risks associated with CVE-2022-46265 include the possibility of users being redirected to malicious websites if exploited.