vendor:
IBM Navigator for i
by:
John Page (aka hyp3rlinx)
6.1
CVSS
HIGH
HTTP Security Token Bypass
862
CWE
Product Name: IBM Navigator for i
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE: CVE-2024-51464
CPE: a:ibm:ibm_navigator_for_i
Platforms Tested: Web-based application (IBM i)
2024
IBM Navigator for i HTTP Security Token Bypass Vulnerability
IBM Navigator for i is vulnerable to a security token bypass issue (CVE-2024-51464). By manipulating the last eight digits of the security token ID, an authenticated attacker can craft a specially designed request to bypass the Navigator for i interface restrictions. This allows the attacker to perform unauthorized operations remotely, exploiting the integrity check mechanism of the web application.
Mitigation:
To mitigate this vulnerability, IBM users are advised to apply the official patch provided by IBM as soon as it is released. Additionally, users should monitor and restrict network access to the IBM Navigator for i interface to trusted sources only.