Required CVE Record Information
Description
IBM Navigator for i 7.3, 7.4 and 7.5 could allow an authenticated user to access IBM Navigator for i log files they are authorized to but not while using this interface. The remote authenticated user can bypass the interface checks and download log files by modifying servlet filter. IBM X-Force ID: 239301.
CWE 1 Total
CVSS 1 Total
Score | Severity | Version | Vector String |
---|---|---|---|
4.3 | MEDIUM | 3.1 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
References 2 Total
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 2 Total
- https://www.ibm.com/support/pages/node/6850801 vendor-advisoryx_transferred
- https://exchange.xforce.ibmcloud.com/vulnerabilities/239301 vdb-entryx_transferred