PT-2022-26977 · Ibm · Ibm Content Navigator
Yousuf Alhajri
·
Published
2022-12-07
·
Updated
2023-06-27
·
CVE-2022-43581
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
IBM Content Navigator versions 3.0.0 through 3.0.12
Description
The issue is related to missing authorization, which could allow an authenticated user to load external plugins and execute code.
Recommendations
For IBM Content Navigator versions 3.0.0 through 3.0.12, update to a version that includes the fix for the missing authorization issue.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Missing Authorization
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ibm Content Navigator