Vulnerability Description
IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to obtain sensitive information they are authorized to but not while using this interface. By performing an SQL injection an attacker could see user profile attributes through this interface. IBM X-Force ID: 239305.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | I | 7.3 |
Related Weaknesses (CWE)
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/239305VDB EntryVendor Advisory
- https://www.ibm.com/support/pages/node/6850801PatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/239305VDB EntryVendor Advisory
- https://www.ibm.com/support/pages/node/6850801PatchVendor Advisory
FAQ
What is CVE-2022-43860?
CVE-2022-43860 is a vulnerability with a CVSS score of 4.3 (MEDIUM). IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to obtain sensitive information they are authorized to but not while using this interface. By performing an SQL injection an at...
How severe is CVE-2022-43860?
CVE-2022-43860 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-43860?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm I.