CVE-2022-22481 Information
Jun 07, 2022
cve
Description
IBM Navigator for i 7.2 7.3 and 7.4 (heritage version) could allow a remote attacker to obtain access to the web interface without valid credentials. By modifying the sign on request an attacker can gain visibility to the fully qualified domain name of the target system and the navigator tasks page however they do not gain the ability to perform those tasks on the system or see any specific system data. IBM X-Force ID: 225899.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Reference
https://www.ibm.com/support/pages/node/6583553 https://exchange.xforce.ibmcloud.com/vulnerabilities/225899
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
NONE
Base Score
NONE
Base Severity
5.3
Share on: