PT-2022-27036 · Ibm · Ibm Navigator For I

Amine Ismail

+1

·

Published

2022-12-22

·

Updated

2022-12-31

·

CVE-2022-43860

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM Navigator for i versions 7.3 through 7.5
Description The issue allows an authenticated user to obtain sensitive information they are authorized to, but not while using this interface, by performing an SQL injection. This could enable an attacker to see user profile attributes through the interface.
Recommendations For versions 7.3 through 7.5, consider restricting access to sensitive user profile attributes until a patch is available. As a temporary workaround, consider disabling SQL injection capabilities in the interface until a fix is provided. Restrict access to user profile attributes to minimize the risk of exploitation.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2022-43860

Affected Products

Ibm Navigator For I