IBM i 7.4 and 7.5 is vulnerable to an authenticated user gaining elevated privilege to a physical file. A user with authority to a view can alter the based-on physical file security attributes without having object management rights to the physical file. A malicious actor can use the elevated privileges to perform actions restricted by their view privileges.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.ibm.com/support/pages/node/7179158 |
History
Wed, 18 Dec 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 18 Dec 2024 11:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | IBM i 7.4 and 7.5 is vulnerable to an authenticated user gaining elevated privilege to a physical file. A user with authority to a view can alter the based-on physical file security attributes without having object management rights to the physical file. A malicious actor can use the elevated privileges to perform actions restricted by their view privileges. | |
Title | IBM i incorrect privilege assignment | |
First Time appeared |
Ibm
Ibm i |
|
Weaknesses | CWE-732 | |
CPEs | cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:* cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:* |
|
Vendors & Products |
Ibm
Ibm i |
|
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: ibm
Published: 2024-12-18T10:53:19.133Z
Updated: 2024-12-18T14:41:39.925Z
Reserved: 2024-09-18T19:26:44.571Z
Link: CVE-2024-47104
Vulnrichment
Updated: 2024-12-18T14:41:31.479Z
NVD
Status : Received
Published: 2024-12-18T11:15:05.763
Modified: 2024-12-18T11:15:05.763
Link: CVE-2024-47104
Redhat
No data.