Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-43857


IBM Navigator for i 7.3, 7.4 and 7.5 could allow an authenticated user to access IBM Navigator for i log files they are authorized to but not while using this interface. The remote authenticated user can bypass the interface checks and download log files by modifying servlet filter. IBM X-Force ID: 239301.


Published

2022-12-22T21:15:10.967

Last Modified

2024-11-21T07:27:16.837

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-22
  • Type: Primary
    CWE-22

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System ibm i 7.3 Yes
Operating System ibm i 7.4 Yes
Operating System ibm i 7.5 Yes

References