First published: Fri May 06 2022(Updated: )
IBM Navigator for i (heritage version) could allow a remote attacker to obtain access to the web interface without valid credentials. By modifying the sign on request, an attacker can gain visibility to the fully qualified domain name of the target system and the navigator tasks page, however they do not gain the ability to perform those tasks on the system or see any specific system data.
Credit: psirt@us.ibm.com psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM i | =7.2 | |
IBM i | =7.3 | |
IBM i | =7.4 | |
<=IBM i 7.4, 7.3, and 7.2 (heritage version) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-22481 is medium with a CVSS score of 5.3.
A remote attacker can exploit CVE-2022-22481 by modifying the sign-on request and gaining access to the web interface without valid credentials.
IBM Navigator for i versions 7.2, 7.3, and 7.4 (heritage version) are affected by CVE-2022-22481.
Yes, IBM has provided a fix for CVE-2022-22481. Please refer to the IBM support page for more information.
You can find more information about CVE-2022-22481 on the IBM X-Force Exchange and the IBM support page.