CVE-2022-22399

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Mar 5, 2024
Updated: Jan 14, 2025
CWE ID 116
CWE ID 644

Summary

CVE-2022-22399 is a vulnerability affecting IBM Aspera Faspex versions 5.0.0 and 5.0.1. This issue stems from inadequate validation of HOST headers, leading to HTTP header injection. An attacker can exploit this vulnerability to execute cross-site scripting attacks, poison caches, or hijack sessions, posing a significant threat to the targeted system. IBM's X-Force has assigned this vulnerability the ID 222562.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share