CVE-2022-46407: Medium severity ericsson network manager vulnerability
Ericsson Network Manager (ENM), versions prior to 22.2, contains a vulnerability in the REST endpoint “editprofile” where Open Redirect HTTP Header Injection can lead to redirection of the submitted request to domain out of control of ENM deployment. The attacker would need admin/elevated access to exploit the vulnerability
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-46407.
What is the severity of CVE-2022-46407?
The severity of CVE-2022-46407 is medium (4.8).
What is the affected software for CVE-2022-46407?
The affected software for CVE-2022-46407 is Ericsson Network Manager (ENM) versions prior to 22.2.
What is the description of CVE-2022-46407?
CVE-2022-46407 is a vulnerability in Ericsson Network Manager (ENM) versions prior to 22.2 where Open Redirect HTTP Header Injection can lead to redirection of the submitted request to a domain out of control of ENM deployment.
How can I fix CVE-2022-46407?
Update to version 22.2 or later of Ericsson Network Manager (ENM) to fix CVE-2022-46407.