Ericsson Network Manager (ENM), versions prior to 22.2, contains a vulnerability in the REST endpoint “editprofile” where Open Redirect HTTP Header Injection can lead to redirection of the submitted request to domain out of control of ENM deployment. The attacker would need admin/elevated access to exploit the vulnerability
Use CWE-601, Ericsson vendor hub and Network Manager product page to widen CVE-2022-46407 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-39909, CVE-2024-25007 and CVE-2025-27258 for nearby disclosures in the same product family. Additional editorial context is available in Why “Low” and “Medium” CVEs Still Breach Networks.