CVE-2022-43858: IBM Navigator for i information disclosure
IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to access the file system and download files they are authorized to but not while using this interface. The remote authenticated user can bypass the interface checks by modifying a parameter thereby gaining access to their files through this interface. IBM X-Force ID: 239303.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2022-43858?
The severity of CVE-2022-43858 is medium.
How does CVE-2022-43858 impact IBM Navigator for i versions 7.3, 7.4, and 7.5?
CVE-2022-43858 allows an authenticated user to access the file system and download files they are authorized to, bypassing interface checks.
Can an authenticated user bypass the interface checks in IBM Navigator for i versions 7.3, 7.4, and 7.5?
Yes, an authenticated user can bypass the interface checks by modifying a parameter.
Which versions of IBM Navigator for i are affected by CVE-2022-43858?
IBM Navigator for i versions 7.3, 7.4, and 7.5 are affected by CVE-2022-43858.
How can I fix CVE-2022-43858?
To fix CVE-2022-43858, apply the necessary security patches provided by IBM.