CVE-2022-43859: IBM Navigator for i SQL injection
IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to obtain sensitive information for an object they are authorized to but not while using this interface. By performing a UNION based SQL injection an attacker could see file permissions through this interface. IBM X-Force ID: 239304.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-43859?
CVE-2022-43859 is a vulnerability in IBM Navigator for i 7.3, 7.4, and 7.5 that allows an authenticated user to obtain sensitive information for an object they are authorized to, but not while using this interface.
What is the severity of CVE-2022-43859?
The severity of CVE-2022-43859 is medium with a severity score of 6.3.
How can an attacker exploit CVE-2022-43859?
An attacker can exploit CVE-2022-43859 by performing a UNION based SQL injection to see file permissions through the IBM Navigator for i interface.
Which versions of IBM Navigator for i are affected by CVE-2022-43859?
IBM Navigator for i versions 7.3, 7.4, and 7.5 are affected by CVE-2022-43859.
How can I find more information about CVE-2022-43859 and its fix?
You can find more information about CVE-2022-43859 and its fix on the IBM X-Force ID page and the IBM support page.