IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to obtain sensitive information for an object they are authorized to but not while using this interface. By performing a UNION based SQL injection an attacker could see file permissions through this interface. IBM X-Force ID: 239304.
2022-12-22T21:15:11.690
2024-11-21T07:27:17.153
Modified
CVSSv3.1: 6.3 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | ibm | i | 7.3 | Yes |
Operating System | ibm | i | 7.4 | Yes |
Operating System | ibm | i | 7.5 | Yes |