Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ppqf-24vq-48jf

Опубликовано: 22 дек. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to obtain sensitive information for an object they are authorized to but not while using this interface. By performing a UNION based SQL injection an attacker could see file permissions through this interface. IBM X-Force ID: 239304.

IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to obtain sensitive information for an object they are authorized to but not while using this interface. By performing a UNION based SQL injection an attacker could see file permissions through this interface. IBM X-Force ID: 239304.

EPSS

Процентиль: 36%
0.00154
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 6.3
nvd
около 3 лет назад

IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to obtain sensitive information for an object they are authorized to but not while using this interface. By performing a UNION based SQL injection an attacker could see file permissions through this interface. IBM X-Force ID: 239304.

CVSS3: 4.3
fstec
около 3 лет назад

Уязвимость графического интерфейса IBM Navigator операционной системы IBM i, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 36%
0.00154
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-89