CVE-2022-43858
- EPSS 0.99%
- Veröffentlicht 22.12.2022 21:15:11
- Zuletzt bearbeitet 21.11.2024 07:27:16
IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to access the file system and download files they are authorized to but not while using this interface. The remote authenticated user can bypass the interface checks by modifying...
CVE-2022-43859
- EPSS 0.58%
- Veröffentlicht 22.12.2022 21:15:11
- Zuletzt bearbeitet 21.11.2024 07:27:17
IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to obtain sensitive information for an object they are authorized to but not while using this interface. By performing a UNION based SQL injection an attacker could see file perm...
CVE-2022-43857
- EPSS 0.99%
- Veröffentlicht 22.12.2022 21:15:10
- Zuletzt bearbeitet 21.11.2024 07:27:16
IBM Navigator for i 7.3, 7.4 and 7.5 could allow an authenticated user to access IBM Navigator for i log files they are authorized to but not while using this interface. The remote authenticated user can bypass the interface checks and download log...
CVE-2022-34358
- EPSS 0.47%
- Veröffentlicht 13.07.2022 17:15:08
- Zuletzt bearbeitet 21.11.2024 07:09:21
IBM i 7.2, 7.3, 7.4, and 7.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trust...
CVE-2022-22495
- EPSS 2.13%
- Veröffentlicht 24.05.2022 17:15:08
- Zuletzt bearbeitet 21.11.2024 06:46:54
IBM i 7.3, 7.4, and 7.5 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 226941.
CVE-2022-22481
- EPSS 1.18%
- Veröffentlicht 09.05.2022 17:15:09
- Zuletzt bearbeitet 21.11.2024 06:46:52
IBM Navigator for i 7.2, 7.3, and 7.4 (heritage version) could allow a remote attacker to obtain access to the web interface without valid credentials. By modifying the sign on request, an attacker can gain visibility to the fully qualified domain na...
CVE-2021-39056
- EPSS 1.31%
- Veröffentlicht 13.01.2022 18:15:07
- Zuletzt bearbeitet 21.11.2024 06:18:30
The IBM i 7.1, 7.2, 7.3, and 7.4 Extended Dynamic Remote SQL server (EDRSQL) could allow a remote authenticated user to send a specially crafted request and cause a denial of service. IBM X-Force ID: 214537.
CVE-2021-38876
- EPSS 0.63%
- Veröffentlicht 30.12.2021 17:15:12
- Zuletzt bearbeitet 21.11.2024 06:18:08
IBM i 7.2, 7.3, and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted se...
CVE-2021-20501
- EPSS 1.34%
- Veröffentlicht 21.04.2021 12:15:08
- Zuletzt bearbeitet 21.11.2024 05:46:40
IBM i 7.1, 7.2, 7.3, and 7.4 SMTP allows a network attacker to send emails to non-existent local-domain recipients to the SMTP server, caused by using a non-default configuration. An attacker could exploit this vulnerability to consume unnecessary ne...
CVE-2020-4345
- EPSS 0.33%
- Veröffentlicht 17.05.2020 14:15:10
- Zuletzt bearbeitet 21.11.2024 05:32:37
IBM i 7.2, 7.3, and 7.4 users running complex SQL statements under a specific set of circumstances may allow a local user to obtain sensitive information that they should not have access to. IBM X-Force ID: 178318.