Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-43860


IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to obtain sensitive information they are authorized to but not while using this interface. By performing an SQL injection an attacker could see user profile attributes through this interface. IBM X-Force ID: 239305.


Published

2022-12-24T00:15:08.783

Last Modified

2024-11-21T07:27:17.323

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-89
  • Type: Primary
    CWE-89

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System ibm i 7.3 Yes
Operating System ibm i 7.4 Yes
Operating System ibm i 7.5 Yes

References