Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-43858


IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to access the file system and download files they are authorized to but not while using this interface. The remote authenticated user can bypass the interface checks by modifying a parameter thereby gaining access to their files through this interface. IBM X-Force ID: 239303.


Published

2022-12-22T21:15:11.357

Last Modified

2024-11-21T07:27:16.990

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-22
  • Type: Primary
    CWE-22

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System ibm i 7.3 Yes
Operating System ibm i 7.4 Yes
Operating System ibm i 7.5 Yes

References