CVE-2022-30610

Severity CVSS v4.0:
Pending analysis
Type:
CWE-269 Improper Privilege Management
Publication date:
10/06/2022
Last modified:
17/06/2022

Description

IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.15.0 is vulnerable to reverse tabnabbing where it could allow a page linked to from within IBM Spectrum Copy Data Management to rewrite it. An administrator could enter a link to a malicious URL that another administrator could then click. Once clicked, that malicious URL could then rewrite the original page with a phishing page. IBM X-Force ID: 227363.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ibm:spectrum_copy_data_management:*:*:*:*:*:*:*:* 2.2.0.0 (including) 2.2.15.0 (including)
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*