Elevated Privilege Vulnerability in IBM i 7.4 and 7.5
CVE-2024-47104

6.8MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
18 December 2024

Summary

CVE-2024-47104 affects IBM i versions 7.4 and 7.5, where authenticated users can exploit a vulnerability to gain elevated privileges over physical file security attributes. Despite lacking object management rights, users with viewing permissions can alter the security configurations of physical files. This allows potentially malicious actions that bypass intended restrictions, posing severe security risks to affected systems. Organizations using IBM i must address this vulnerability to maintain the integrity and security of their file management systems.

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.