VYPR
Unrated severityNVD Advisory· Published Dec 18, 2024· Updated Dec 18, 2024

IBM i incorrect privilege assignment

CVE-2024-47104

Description

IBM i 7.4 and 7.5 is vulnerable to an authenticated user gaining elevated privilege to a physical file. A user with authority to a view can alter the based-on physical file security attributes without having object management rights to the physical file. A malicious actor can use the elevated privileges to perform actions restricted by their view privileges.

Affected products

1
  • IBM/Iv5
    cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
    Range: 7.4, 7.5

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.