PT-2023-14930 · Ericsson · Ericsson Network Manager

Andrea Carlo Maria Dattola

+1

·

Published

2023-06-29

·

Updated

2023-07-06

·

CVE-2022-46407

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Ericsson Network Manager (ENM) versions prior to 22.2
Description The issue concerns a vulnerability in the REST endpoint "editprofile" where Open Redirect HTTP Header Injection can occur, potentially leading to the redirection of submitted requests to domains outside the control of the ENM deployment. An attacker would need admin or elevated access to exploit this issue.
Recommendations For versions prior to 22.2, update to version 22.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the "editprofile" endpoint to minimize the risk of exploitation.

Fix

Open Redirect

Weakness Enumeration

Related Identifiers

CVE-2022-46407

Affected Products

Ericsson Network Manager