CVE-2022-43858
IBM Navigator for i information disclosure
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to access the file system and download files they are authorized to but not while using this interface. The remote authenticated user can bypass the interface checks by modifying a parameter thereby gaining access to their files through this interface. IBM X-Force ID: 239303.
IBM Navigator para i 7.3, 7.4 y 7.5 podría permitir que un usuario autenticado acceda al sistema de archivos y descargue archivos para los que está autorizado, pero no mientras usa esta interfaz. El usuario autenticado remotamente puede eludir las comprobaciones de la interfaz modificando un parámetro y obteniendo así acceso a sus archivos a través de esta interfaz. ID de IBM X-Force: 239303.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-10-26 CVE Reserved
- 2022-12-22 CVE Published
- 2024-07-14 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.ibm.com/support/pages/node/6850801 | 2023-11-07 |
URL | Date | SRC |
---|---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/239303 | 2023-11-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ibm Search vendor "Ibm" | I Search vendor "Ibm" for product "I" | 7.3 Search vendor "Ibm" for product "I" and version "7.3" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | I Search vendor "Ibm" for product "I" | 7.4 Search vendor "Ibm" for product "I" and version "7.4" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | I Search vendor "Ibm" for product "I" | 7.5 Search vendor "Ibm" for product "I" and version "7.5" | - |
Affected
|