vendor:
                    Navigator for i
                by:
                    John Page (aka hyp3rlinx)
                6.1
                        CVSS
                    HIGH
                    Server Side Request Forgery (SSRF)
                    918
                        CWE
                    Product Name: Navigator for i
                    Affected Version From:  Unknown
                    Affected Version To:  Unknown
                    Patch Exists: NO
                    Related CWE: CVE-2024-51463
                    CPE:  a:ibm:navigator_for_i
                    Platforms Tested:  
                    2024
                    IBM Navigator for i Server-Side Request Forgery (SSRF) Bypass
An SSRF vulnerability in IBM Navigator for i allows an authenticated attacker to send unauthorized requests from the system, potentially enabling network enumeration or other attacks. The vulnerability exploits a HTTP servlet generated security token bypass (CVE-2024-51464), allowing attackers to abuse the 'testConnectPort' servlet method to connect to any IP and PORT outside of the LAN, bypassing firewall rules and potentially connecting to attacker-controlled infrastructure.
Mitigation:
					To mitigate this vulnerability, IBM recommends applying the necessary patches provided by the vendor to address the SSRF bypass issue in IBM Navigator for i.