CVE-2025-2950

CVSS 3.1 Score 5.4 of 10 (medium)

Details

Published Apr 18, 2025
Updated: Apr 21, 2025
CWE ID 644

Summary

CVE-2025-2950 is a vulnerability affecting IBM i 7.3, 7.4, 7.5, and 7.5 systems. The issue lies with IBM Navigator for i, which fails to adequately filter HTTP header content. An authenticated user can exploit this vulnerability by manipulating the host header in HTTP requests. By changing the domain/IP address in these requests, unexpected behavior can occur. This issue poses a serious security risk, as attackers could potentially gain unauthorized access to sensitive information or perform unintended actions.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share