TROYANOSYVIRUS
Back to CVEs

CVE-2022-30610

MEDIUM
4.5

Description

IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.15.0 is vulnerable to reverse tabnabbing where it could allow a page linked to from within IBM Spectrum Copy Data Management to rewrite it. An administrator could enter a link to a malicious URL that another administrator could then click. Once clicked, that malicious URL could then rewrite the original page with a phishing page. IBM X-Force ID: 227363.

CVE Details

CVSS v3.1 Score4.5
SeverityMEDIUM
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredHIGH
User InteractionREQUIRED
Published6/10/2022
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0

Affected Products

ibm:spectrum_copy_data_managementlinux:linux_kernel

Weaknesses (CWE)

CWE-269

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.