PT-2022-27034 · Ibm · Ibm Navigator For I

Amine Ismail

+1

·

Published

2022-12-22

·

Updated

2022-12-28

·

CVE-2022-43857

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Navigator for i versions 7.3 through 7.5
Description The issue allows an authenticated user to access IBM Navigator for i log files they are authorized to, but not while using this interface. The remote authenticated user can bypass the interface checks and download log files by modifying the servlet filter.
Recommendations For versions 7.3 through 7.5, consider restricting access to the servlet filter to prevent unauthorized log file downloads until a patch is available. As a temporary workaround, modifying the interface checks to prevent bypassing can help minimize the risk of exploitation.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2022-43857

Affected Products

Ibm Navigator For I