• The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
Menu
  • The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
  • Multiple Vulnerabilities Pop Up In Navigator For i

    January 23, 2023 Timothy Prickett Morgan

    Why do we network computers again? Remind me.

    A new security bulletin was released for the Navigator for i system management interface for the IBM i platform on January 18, which rolls up four different vulnerabilities for Navigator for i that leave it open to log file access, to obtaining file attributes, and to SQL Injection attacks due to multiple other vulnerabilities.

    You can read about this security bulletin at this link. The most severe of the issues is the SQL injection attack, which has a CVSS Base score of 6.3 out of 10. According to the bulletin: “IBM Navigator for i 7.3, 7.4, and 7.5 could allow an authenticated user to obtain sensitive information for an object they are authorized to but not while using this interface. By performing a UNION based SQL injection an attacker could see file permissions through this interface.”

    Access to log files for Navigator for i 7.3, 7.4, and 7.5 is unintentionally allowed when a remote authenticated user can bypass the interface checks in the tool and download log files by modifying the servlet filter for Navigator for i. This one has a CVSS rating of 4.3. Another vulnerability allows an authenticated user to get files they are authorized to get but not through the Navigator for i toll (this seems like a minor problem if you as me), and yet another one allowed attackers to see user profile attributes why performing an SQL injection.

    IBM is providing fixes for these vulnerabilities for IBM i 7.3, IBM i 7.4, and IBM i 7.5. The following PTFs patch Navigator for i up against these vulnerabilities:

    • For IBM i 7.5, HTTP Server for i Group PTF Level SF99952 – 05: SF99952 750 IBM HTTP Server for i – level 5
    • For IBM i 7.4, HTTP Server for i Group PTF Level SF99662 – 25: SF99662 740 IBM HTTP Server for i – level 25
    • For IBM i 7.3, HTTP Server for i Group PTF Level SF99722 – 42: SF99722 730 IBM HTTP Server for i – level 42

    The CVE record dates for these vulnerabilities was October 26, 2022, and we remind you that this record date is not necessarily when the vulnerability was first known to customers or IBM. But it certainly was not after that date!

    RELATED STORIES

    New Nav for i Brings New Stuff to You

    What’s New in IBM i Services and Networking

    IBM Delivers More Out-of-the-Box Security with IBM i 7.5

    Announcement Day: IBM Lifts The Veil On IBM i 7.5 And 7.4 TR6

    IBM Accelerates New Nav Development Following Log4j Issue

    No Plan To Support New Nav on Older IBM i Releases, IBM Says

    Log4j Hits Heritage Version of Navigator for i – No Patch Coming

    IBM Ships ACS Version 1.1.9.0

    New Nav Puts SQL Services Within Reach

    Navigator For IBM i On A Zigzag Journey

    IBM Navigator for i Increases Web and Mobile Effort

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    Tags: Tags: IBM i, IBM i 7.3, IBM i 7.4, IBM i 7.5, Navigator for i, SQL

    Sponsored by
    WorksRight Software

    Do you need area code information?
    Do you need ZIP Code information?
    Do you need ZIP+4 information?
    Do you need city name information?
    Do you need county information?
    Do you need a nearest dealer locator system?

    We can HELP! We have affordable AS/400 software and data to do all of the above. Whether you need a simple city name retrieval system or a sophisticated CASS postal coding system, we have it for you!

    The ZIP/CITY system is based on 5-digit ZIP Codes. You can retrieve city names, state names, county names, area codes, time zones, latitude, longitude, and more just by knowing the ZIP Code. We supply information on all the latest area code changes. A nearest dealer locator function is also included. ZIP/CITY includes software, data, monthly updates, and unlimited support. The cost is $495 per year.

    PER/ZIP4 is a sophisticated CASS certified postal coding system for assigning ZIP Codes, ZIP+4, carrier route, and delivery point codes. PER/ZIP4 also provides county names and FIPS codes. PER/ZIP4 can be used interactively, in batch, and with callable programs. PER/ZIP4 includes software, data, monthly updates, and unlimited support. The cost is $3,900 for the first year, and $1,950 for renewal.

    Just call us and we’ll arrange for 30 days FREE use of either ZIP/CITY or PER/ZIP4.

    WorksRight Software, Inc.
    Phone: 601-856-8337
    Fax: 601-856-9432
    Email: software@worksright.com
    Website: www.worksright.com

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    Participate In The 2023 IBM i Marketplace Survey Discussion 2023 IBM i Predictions, Part 2

    Leave a Reply Cancel reply

TFH Volume: 33 Issue: 3

This Issue Sponsored By

  • ProData
  • New Generation Software
  • WorksRight Software
  • Raz-Lee Security
  • Manta Technologies

Table of Contents

  • It Is Time To Have A Group Chat About AI
  • 2023 IBM i Predictions, Part 2
  • Multiple Vulnerabilities Pop Up In Navigator For i
  • Participate In The 2023 IBM i Marketplace Survey Discussion
  • IBM i PTF Guide, Volume 25, Number 4

Content archive

  • The Four Hundred
  • Four Hundred Stuff
  • Four Hundred Guru

Recent Posts

  • Liam Allan Shares What’s Coming Next With Code For IBM i
  • From Stable To Scalable: Visual LANSA 16 Powers IBM i Growth – Launching July 8
  • VS Code Will Be The Heart Of The Modern IBM i Platform
  • The AS/400: A 37-Year-Old Dog That Loves To Learn New Tricks
  • IBM i PTF Guide, Volume 27, Number 25
  • Meet The Next Gen Of IBMers Helping To Build IBM i
  • Looks Like IBM Is Building A Linux-Like PASE For IBM i After All
  • Will Independent IBM i Clouds Survive PowerVS?
  • Now, IBM Is Jacking Up Hardware Maintenance Prices
  • IBM i PTF Guide, Volume 27, Number 24

Subscribe

To get news from IT Jungle sent to your inbox every week, subscribe to our newsletter.

Pages

  • About Us
  • Contact
  • Contributors
  • Four Hundred Monitor
  • IBM i PTF Guide
  • Media Kit
  • Subscribe

Search

Copyright © 2025 IT Jungle