CVE-2022-46407
Last modified
CVE-2022-46407 is a medium-severity vulnerability rated 4.8/10 on the CVSS scale. Ericsson Network Manager (ENM), versions prior to 22.2, contains a vulnerability in the REST endpoint “editprofile” where Open Redirect HTTP Header Injection can lead to redirection of the submitted request to domain out of control of ENM deployment. The attacker would need admin/elevated access to exploit the vulnerability. EPSS estimates a 0.30% chance of exploitation in the next 30 days.
Description
Ericsson Network Manager (ENM), versions prior to 22.2, contains a vulnerability in the REST endpoint “editprofile” where Open Redirect HTTP Header Injection can lead to redirection of the submitted request to domain out of control of ENM deployment. The attacker would need admin/elevated access to exploit the vulnerability
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ericsson | Network Manager | < 22.2 |
References
- https://www.gruppotim.it/it/footer/red-team.htmlThird Party Advisory
- https://www.gruppotim.it/it/footer/red-team.htmlThird Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-46407?
How severe is CVE-2022-46407?
How do I fix CVE-2022-46407?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-46400The Microchip RN4870 module firmware 1.43 (and the Microchip…5.4
- CVE-2022-46401The Microchip RN4870 module firmware 1.43 (and the Microchip…5.4
- CVE-2022-46402The Microchip RN4870 module firmware 1.43 (and the Microchip…6.5
- CVE-2022-46403The Microchip RN4870 module firmware 1.43 (and the Microchip…8.6
- CVE-2022-46404A command injection vulnerability has been identified in Ato…9.8
- CVE-2022-46405Mastodon through 4.0.2 allows attackers to cause a denial of…7.5
- CVE-2022-46408Ericsson Network Manager (ENM), versions prior to 22.1, cont…6.8
- CVE-2022-4641A vulnerability was found in pig-vector and classified as pr…5.5
- CVE-2022-46410An issue was discovered in Veritas NetBackup Flex Scale thro…8.8
- CVE-2022-46411An issue was discovered in Veritas NetBackup Flex Scale thro…8.8
- CVE-2022-46412An issue was discovered in Veritas NetBackup Flex Scale thro…8.8
- CVE-2022-46413An issue was discovered in Veritas NetBackup Flex Scale thro…8.8
Are you affected by CVE-2022-46407?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
