CVE-2022-43860SQL Injection in IBM Navigator FOR I

CWE-89SQL Injection3 documents3 sources
Severity
4.3MEDIUMNVD
EPSS
0.1%
top 73.52%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 24

Description

IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to obtain sensitive information they are authorized to but not while using this interface. By performing an SQL injection an attacker could see user profile attributes through this interface. IBM X-Force ID: 239305.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages2 packages

CVEListV5ibm/navigator_for_i7.3, 7.4, 7.5
NVDibm/i7.3, 7.4, 7.5+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-gph8-h9xc-35r4: IBM Navigator for i 72022-12-24
CVEList
IBM Navigator for i SQL injection2022-12-22
CVE-2022-43860 — SQL Injection in IBM Navigator FOR I | cvebase