HIGH
IBM i privilege escalation
Published Oct 29, 2023
7.8
HIGHCVSS 3.1
EPSS 0.14%
Description
Management Central as part of IBM i 7.2, 7.3, 7.4, and 7.5 Navigator contains a local privilege escalation vulnerability. A malicious actor with command line access to the operating system can exploit this vulnerability to elevate privileges to gain component access to the operating system. IBM X-Force ID: 264114.
Affected products
-
- Version 7.2, 7.3, 7.4, 7.5StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| IBM | n/a | unaffected |
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://exchange.xforce.ibmcloud.com/vulnerabilities/264114 vdb-entryVDB EntryVendor Advisory
- https://www.ibm.com/support/pages/node/7060686 vendor-advisoryPatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://exchange.xforce.ibmcloud.com/vulnerabilities/264114 | vdb-entryVDB EntryVendor Advisory | |
| https://www.ibm.com/support/pages/node/7060686 | vendor-advisoryPatchVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner ibm
Published Oct 29, 2023
Updated Sep 6, 2024
Reserved Aug 18, 2023
Link CVE-2023-40686
CISA Vulnrichment
Updated Sep 6, 2024