Unrated severityNVD Advisory· Published Dec 18, 2024· Updated Dec 18, 2024
IBM i incorrect privilege assignment
CVE-2024-47104
Description
IBM i 7.4 and 7.5 is vulnerable to an authenticated user gaining elevated privilege to a physical file. A user with authority to a view can alter the based-on physical file security attributes without having object management rights to the physical file. A malicious actor can use the elevated privileges to perform actions restricted by their view privileges.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.ibm.com/support/pages/node/7179158mitrevendor-advisory
News mentions
0No linked articles in our index yet.