Lucene search

K
cve[email protected]CVE-2024-25050
HistoryApr 28, 2024 - 1:15 p.m.

CVE-2024-25050

2024-04-2813:15:08
CWE-427
web.nvd.nist.gov
29
ibm i
rational development studio
networking
elevated privileges
unqualified library call
administrator
vulnerability
user-controlled code
x-force
nvd

8.4 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

6.6 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

15.7%

IBM i 7.2, 7.3, 7.4, 7.5 and IBM Rational Development Studio for i 7.2, 7.3, 7.4, 7.5 networking and compiler infrastructure could allow a local user to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-controlled code to run with administrator privileges. IBM X-Force ID: 283242.

Affected configurations

Vulners
Node
ibmiMatch7.2
OR
ibmiMatch7.3
OR
ibmiMatch7.4
OR
ibmiMatch7.5
OR
ibmrational_application_developer_for_websphereMatch7.2
OR
ibmrational_application_developer_for_websphereMatch7.3
OR
ibmrational_application_developer_for_websphereMatch7.4
OR
ibmrational_application_developer_for_websphereMatch7.5
VendorProductVersionCPE
ibmi7.2cpe:2.3:o:ibm:i:7.2:*:*:*:*:*:*:*
ibmi7.3cpe:2.3:o:ibm:i:7.3:*:*:*:*:*:*:*
ibmi7.4cpe:2.3:o:ibm:i:7.4:*:*:*:*:*:*:*
ibmi7.5cpe:2.3:o:ibm:i:7.5:*:*:*:*:*:*:*
ibmrational_application_developer_for_websphere7.2cpe:2.3:a:ibm:rational_application_developer_for_websphere:7.2:*:*:*:*:*:*:*
ibmrational_application_developer_for_websphere7.3cpe:2.3:a:ibm:rational_application_developer_for_websphere:7.3:*:*:*:*:*:*:*
ibmrational_application_developer_for_websphere7.4cpe:2.3:a:ibm:rational_application_developer_for_websphere:7.4:*:*:*:*:*:*:*
ibmrational_application_developer_for_websphere7.5cpe:2.3:a:ibm:rational_application_developer_for_websphere:7.5:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "i",
    "vendor": "IBM",
    "versions": [
      {
        "status": "affected",
        "version": "7.2, 7.3, 7.4, 7.5"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "Rational Development Studio for i",
    "vendor": "IBM",
    "versions": [
      {
        "status": "affected",
        "version": "7.2, 7.3, 7.4, 7.5"
      }
    ]
  }
]

8.4 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

6.6 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

15.7%

Related for CVE-2024-25050