CVE-2022-43860: IBM Navigator for i SQL injection
IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to obtain sensitive information they are authorized to but not while using this interface. By performing an SQL injection an attacker could see user profile attributes through this interface. IBM X-Force ID: 239305.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this IBM Navigator for i vulnerability?
The vulnerability ID for this IBM Navigator for i vulnerability is CVE-2022-43860.
Which versions of IBM Navigator for i are affected by this vulnerability?
Versions 7.3, 7.4, and 7.5 of IBM Navigator for i are affected by this vulnerability.
What is the severity rating for this IBM Navigator for i vulnerability?
The severity rating for this IBM Navigator for i vulnerability is medium, with a value of 4.3.
How can an authenticated user exploit this vulnerability?
An authenticated user can exploit this vulnerability by performing an SQL injection to obtain sensitive information they are authorized to.
Is there a fix available for this vulnerability?
Please refer to the IBM support page for information on available fixes for this vulnerability.