CVE-2022-43859

IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to obtain sensitive information for an object they are authorized to but not while using this interface. By performing a UNION based SQL injection an attacker could see file permissions through this interface. IBM X-Force ID: 239304.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.5:*:*:*:*:*:*:*

History

21 Nov 2024, 07:27

Type Values Removed Values Added
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/239304 - VDB Entry () https://exchange.xforce.ibmcloud.com/vulnerabilities/239304 - VDB Entry
References () https://www.ibm.com/support/pages/node/6850801 - Patch, Vendor Advisory () https://www.ibm.com/support/pages/node/6850801 - Patch, Vendor Advisory
Summary
  • (es) IBM Navigator para i 7.3, 7.4 y 7.5 podría permitir a un usuario autenticado obtener información confidencial para un objeto para el que está autorizado pero no mientras utiliza esta interfaz. Al realizar una inyección SQL basada en UNION, un atacante podría ver los permisos de los archivos a través de esta interfaz. ID de IBM X-Force: 239304.
CVSS v2 : unknown
v3 : 4.3
v2 : unknown
v3 : 6.3

Information

Published : 2022-12-22 21:15

Updated : 2024-11-21 07:27


NVD link : CVE-2022-43859

Mitre link : CVE-2022-43859

CVE.ORG link : CVE-2022-43859


JSON object : View

Products Affected

ibm

  • i
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')