IBM Navigator for i 7.3, 7.4 and 7.5 could allow an authenticated user to access IBM Navigator for i log files they are authorized to but not while using this interface. The remote authenticated user can bypass the interface checks and download log files by modifying servlet filter. IBM X-Force ID: 239301.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 16 Apr 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-04-15T14:16:30.588Z
Reserved: 2022-10-26T15:46:22.823Z
Link: CVE-2022-43857
Updated: 2024-08-03T13:40:06.577Z
Status : Modified
Published: 2022-12-22T21:15:10.967
Modified: 2024-11-21T07:27:16.837
Link: CVE-2022-43857
No data.
OpenCVE Enrichment
No data.
Weaknesses