CVE-2025-2950

MEDIUM

IBM i Navigator - Host Header Injection

Title source: manual
STIX 2.1

Description

IBM i 7.3, 7.4, 7.5, and 7.5 is vulnerable to a host header injection attack caused by improper neutralization of HTTP header content by IBM Navigator for i. An authenticated user can manipulate the host header in HTTP requests to change domain/IP address which may lead to unexpected behavior.

References (1)

Core 1
Core References
Vendor Advisory vendor-advisory patch
https://www.ibm.com/support/pages/node/7231320

Scores

CVSS v3 5.4
EPSS 0.0017
EPSS Percentile 38.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-644
Status published
Products (4)
ibm/i 7.3
ibm/i 7.4
ibm/i 7.5
ibm/i 7.6
Published Apr 18, 2025
Tracked Since Feb 18, 2026