Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-2950


IBM i 7.3, 7.4, 7.5, and 7.5 is vulnerable to a host header injection attack caused by improper neutralization of HTTP header content by IBM Navigator for i. An authenticated user can manipulate the host header in HTTP requests to change domain/IP address which may lead to unexpected behavior.


Published

2025-04-18T15:15:58.937

Last Modified

2025-07-03T20:53:15.263

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 5.4 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-644

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ibm i 7.3 Yes
Application ibm i 7.4 Yes
Application ibm i 7.5 Yes
Application ibm i 7.6 Yes
Operating System ibm i - No

References