CVE-2022-22399
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Mar 5, 2024
Updated: Jan 14, 2025
CWE ID 116
CWE ID 644
Summary
CVE-2022-22399 is a vulnerability affecting IBM Aspera Faspex versions 5.0.0 and 5.0.1. This issue stems from inadequate validation of HOST headers, leading to HTTP header injection. An attacker can exploit this vulnerability to execute cross-site scripting attacks, poison caches, or hijack sessions, posing a significant threat to the targeted system. IBM's X-Force has assigned this vulnerability the ID 222562.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.