Description
IBM i 7.2, 7.3, 7.4, 7.5 and IBM Rational Development Studio for i 7.2, 7.3, 7.4, 7.5 networking and compiler infrastructure could allow a local user to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-controlled code to run with administrator privileges. IBM X-Force ID: 283242.
CVSS breakdown
CVSS 3.1
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected products
- ibm / i7.2, 7.3, 7.4, 7.5 – 7.2, 7.3, 7.4, 7.5
- ibm / Rational Development Studio for i7.2, 7.3, 7.4, 7.5 – 7.2, 7.3, 7.4, 7.5