Vulnerability Name: | CVE-2022-22481 (CCN-225899) | ||||||||||||
Assigned: | 2022-05-06 | ||||||||||||
Published: | 2022-05-06 | ||||||||||||
Updated: | 2022-05-17 | ||||||||||||
Summary: | IBM Navigator for i 7.2, 7.3, and 7.4 (heritage version) could allow a remote attacker to obtain access to the web interface without valid credentials. By modifying the sign on request, an attacker can gain visibility to the fully qualified domain name of the target system and the navigator tasks page, however they do not gain the ability to perform those tasks on the system or see any specific system data. IBM X-Force ID: 225899. | ||||||||||||
CVSS v3 Severity: | 5.3 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N) 4.6 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
3.2 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||||||
Vulnerability Type: | CWE-862 | ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2022-22481 Source: XF Type: UNKNOWN ibm-i-cve202222481-info-disc(225899) Source: XF Type: VDB Entry, Vendor Advisory ibm-i-cve202222481-info-disc (225899) Source: CCN Type: IBM Security Bulletin 6583553 (i) IBM i components are vulnerable to data access due to CVE-2022-22481 Source: CONFIRM Type: Patch, Vendor Advisory https://www.ibm.com/support/pages/node/6583553 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||
BACK |