PT-2023-14930 · Ericsson · Ericsson Network Manager

Andrea Carlo Maria Dattola

+1

·

Publicado

2023-06-29

·

Atualizado

2023-07-06

·

CVE-2022-46407

CVSS v3.1

4.8

Média

VetorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Ericsson Network Manager (ENM) versions prior to 22.2
Description The issue concerns a vulnerability in the REST endpoint "editprofile" where Open Redirect HTTP Header Injection can occur, potentially leading to the redirection of submitted requests to domains outside the control of the ENM deployment. An attacker would need admin or elevated access to exploit this issue.
Recommendations For versions prior to 22.2, update to version 22.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the "editprofile" endpoint to minimize the risk of exploitation.

Correção

Open Redirect

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2022-46407

Produtos afetados

Ericsson Network Manager