CVE-2022-43858
NixOS vulnerability analysis and mitigation

Overview

IBM Navigator for i versions 7.3, 7.4, and 7.5 contains a vulnerability that allows authenticated users to access files they are authorized to access but should not be able to access through the Navigator interface. The vulnerability was discovered and disclosed in December 2022, affecting the IBM i operating system's web-based administration interface (IBM Security Bulletin).

Technical details

The vulnerability allows remote authenticated users to bypass interface checks by modifying parameters, thereby gaining unauthorized access to files through the Navigator interface. The vulnerability has been assigned a CVSS v3.1 base score of 4.3 (MEDIUM) with the vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N. It has been classified as a Path Traversal vulnerability (CWE-22) (NVD).

Impact

The vulnerability enables authenticated users to access and download files they are authorized to access at the system level but should not be able to access through the Navigator interface. While the impact is limited to files the user already has authorization to access, it represents a bypass of intended access control mechanisms within the Navigator interface (IBM Security Bulletin).

Mitigation and workarounds

IBM has released fixes for this vulnerability through the IBM HTTP Server for i Group PTF. The specific PTF levels required are: SF99952 level 5 for version 7.5, SF99662 level 25 for version 7.4, and SF99722 level 42 for version 7.3. These fixes can be obtained through IBM Fix Central (IBM Security Bulletin).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-48606HIGH7.8
  • NixOSNixOS
  • android
NoNoDec 08, 2025
CVE-2025-48639HIGH7.3
  • NixOSNixOS
  • android
NoNoDec 08, 2025
CVE-2025-48625HIGH7
  • NixOSNixOS
  • android
NoNoDec 08, 2025
CVE-2025-48608MEDIUM5.5
  • NixOSNixOS
  • android
NoNoDec 08, 2025
CVE-2025-48569MEDIUM5.5
  • NixOSNixOS
  • android
NoNoDec 08, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management