PT-2022-27036 · Ibm · Ibm Navigator For I
Amine Ismail
+1
·
Published
2022-12-22
·
Updated
2022-12-31
·
CVE-2022-43860
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Navigator for i versions 7.3 through 7.5
Description
The issue allows an authenticated user to obtain sensitive information they are authorized to, but not while using this interface, by performing an SQL injection. This could enable an attacker to see user profile attributes through the interface.
Recommendations
For versions 7.3 through 7.5, consider restricting access to sensitive user profile attributes until a patch is available.
As a temporary workaround, consider disabling SQL injection capabilities in the interface until a fix is provided.
Restrict access to user profile attributes to minimize the risk of exploitation.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Navigator For I