Stack-Based Buffer Overflow in IBM i2 Analyst's Notebook Affects Multiple Versions
CVE-2021-39049

5.3MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
13 December 2021

Summary

IBM i2 Analyst's Notebook versions 9.2.0, 9.2.1, and 9.2.2 are susceptible to a stack-based buffer overflow due to insufficient bounds checking. This vulnerability allows local attackers to exploit the overflow, potentially gaining lower-level privileges within the affected software environment, compromising system integrity. For further details and mitigation strategies, you can refer to IBM's official documentation.

Affected Version(s)

i2 Analyst's Notebook 9.2.0

i2 Analyst's Notebook 9.2.1

i2 Analyst's Notebook 9.2.2

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.