IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to obtain sensitive information they are authorized to but not while using this interface. By performing an SQL injection an attacker could see user profile attributes through this interface. IBM X-Force ID: 239305.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: ibm
Published: 2022-12-22T20:53:16.772Z
Updated: 2024-08-03T13:40:06.698Z
Reserved: 2022-10-26T15:46:22.823Z
Link: CVE-2022-43860
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-12-24T00:15:08.783
Modified: 2024-11-21T07:27:17.323
Link: CVE-2022-43860
Redhat
No data.