First published: Wed Dec 07 2022(Updated: )
IBM Content Navigator 3.0.0, 3.0.1, 3.0.2, 3.0.3, 3.0.4, 3.0.5, 3.0.6, 3.0.7, 3.0.8, 3.0.9, 3.0.10, 3.0.11, and 3.0.12 is vulnerable to missing authorization and could allow an authenticated user to load external plugins and execute code. IBM X-Force ID: 238805.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Content Navigator | <=3.0.0 - 3.0.12 | |
IBM Content Navigator | >=3.0.0<=3.0.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2022-43581.
The severity of CVE-2022-43581 is high with a severity value of 8.8.
The affected software for CVE-2022-43581 is IBM Content Navigator versions 3.0.0 to 3.0.12.
CVE-2022-43581 is a vulnerability in IBM Content Navigator versions 3.0.0 to 3.0.12 that allows an authenticated user to load external plugins and execute code due to missing authorization.
To fix CVE-2022-43581, it is recommended to apply the latest security patch or update to a non-vulnerable version of IBM Content Navigator.