CVE-2024-38330

IBM System Management for i 7.2, 7.3, and 7.4 could allow a local user to gain elevated privileges due to an unqualified library program call. A malicious actor could cause user-controlled code to run with administrator privilege. IBM X-Force ID: 295227.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:i:7.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*

History

11 Jul 2024, 14:53

Type Values Removed Values Added
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/295227 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/295227 - VDB Entry, Vendor Advisory
References () https://www.ibm.com/support/pages/node/7159615 - () https://www.ibm.com/support/pages/node/7159615 - Vendor Advisory
CPE cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
First Time Ibm
Ibm i
CVSS v2 : unknown
v3 : 7.0
v2 : unknown
v3 : 7.8

08 Jul 2024, 15:49

Type Values Removed Values Added
Summary
  • (es) IBM System Management para i 7.2, 7.3 y 7.4 podría permitir que un usuario local obtenga privilegios elevados debido a una llamada no calificada a un programa de librería. Un actor malintencionado podría provocar que el código controlado por el usuario se ejecute con privilegios de administrador. ID de IBM X-Force: 295227.

08 Jul 2024, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-08 02:15

Updated : 2024-07-11 14:53


NVD link : CVE-2024-38330

Mitre link : CVE-2024-38330

CVE.ORG link : CVE-2024-38330


JSON object : View

Products Affected

ibm

  • i
CWE
CWE-427

Uncontrolled Search Path Element