CVE-2022-43857: IBM Navigator for i information disclosure
IBM Navigator for i 7.3, 7.4 and 7.5 could allow an authenticated user to access IBM Navigator for i log files they are authorized to but not while using this interface. The remote authenticated user can bypass the interface checks and download log files by modifying servlet filter. IBM X-Force ID: 239301.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this IBM Navigator for i security vulnerability?
The vulnerability ID for this IBM Navigator for i security vulnerability is CVE-2022-43857.
What is the severity rating of CVE-2022-43857?
The severity rating of CVE-2022-43857 is medium, with a value of 4.3.
Which versions of IBM Navigator for i are affected by CVE-2022-43857?
IBM Navigator for i versions 7.3, 7.4, and 7.5 are affected by CVE-2022-43857.
How can an authenticated user exploit CVE-2022-43857?
An authenticated user can exploit CVE-2022-43857 by bypassing interface checks and downloading unauthorized log files by modifying the servlet filter.
Is there a fix available for CVE-2022-43857?
To fix CVE-2022-43857, users should apply the necessary patches or updates provided by IBM.