Stack-Based Buffer Overflow in IBM i2 Analyst's Notebook
CVE-2021-39050

5.3MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
13 December 2021

Summary

IBM i2 Analyst's Notebook versions 9.2.0, 9.2.1, and 9.2.2 are susceptible to a stack-based buffer overflow due to improper bounds checking. This flaw allows a local attacker to exploit the vulnerability, potentially leading to unauthorized privilege escalation and the execution of arbitrary code. It is crucial for users to implement security measures and updates to mitigate these risks.

Affected Version(s)

i2 Analyst's Notebook 9.2.0

i2 Analyst's Notebook 9.2.1

i2 Analyst's Notebook 9.2.2

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.