Vulnerability Description
IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to access the file system and download files they are authorized to but not while using this interface. The remote authenticated user can bypass the interface checks by modifying a parameter thereby gaining access to their files through this interface. IBM X-Force ID: 239303.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | I | 7.3 |
Related Weaknesses (CWE)
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/239303VDB EntryVendor Advisory
- https://www.ibm.com/support/pages/node/6850801PatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/239303VDB EntryVendor Advisory
- https://www.ibm.com/support/pages/node/6850801PatchVendor Advisory
FAQ
What is CVE-2022-43858?
CVE-2022-43858 is a vulnerability with a CVSS score of 4.3 (MEDIUM). IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to access the file system and download files they are authorized to but not while using this interface. The remote authenticated...
How severe is CVE-2022-43858?
CVE-2022-43858 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-43858?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm I.