CVE-2025-2950: IBM i improper HTTP header neutralization
IBM i 7.3, 7.4, 7.5, and 7.5 is vulnerable to a host header injection attack caused by improper neutralization of HTTP header content by IBM Navigator for i. An authenticated user can manipulate the host header in HTTP requests to change domain/IP address which may lead to unexpected behavior.
Other sources
IBM i is vulnerable to a host header injection attack caused by improper neutralization of HTTP header content by IBM Navigator for i. An authenticated user can manipulate the host header in HTTP requests to change domain/IP address which may lead to unexpected behavior.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2950?
CVE-2025-2950 has been categorized as a medium severity vulnerability.
How do I fix CVE-2025-2950?
To fix CVE-2025-2950, update IBM i systems to the latest version provided by IBM.
What products are affected by CVE-2025-2950?
CVE-2025-2950 affects IBM i versions 7.3, 7.4, 7.5, and any associated IBM iSeries AS/400 products.
What type of attack is CVE-2025-2950 associated with?
CVE-2025-2950 is associated with a host header injection attack.
What could be the impact of CVE-2025-2950?
The impact of CVE-2025-2950 may include unauthorized manipulation of domain/IP address, leading to unexpected behavior.