We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
IBM i 7.3, 7.4, 7.5, and 7.5 is vulnerable to a host header injection attack caused by improper neutralization of HTTP header content by IBM Navigator for i. An authenticated user can manipulate the host header in HTTP requests to change domain/IP address which may lead to unexpected behavior.
Reserved 2025-03-29 | Published 2025-04-18 | Updated 2025-04-18 | Assigner ibmCWE-644 Improper Neutralization of HTTP Headers for Scripting Syntax
www.ibm.com/support/pages/node/7231320
Support options