CVE-2023-40378

Severity
7.8HIGH
EPSS
0.0%
top 93.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 15

Description

IBM Directory Server for IBM i contains a local privilege escalation vulnerability. A malicious actor with command line access to the host operating system can elevate privileges to gain component access to the host operating system. IBM X-Force ID: 263584.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:LExploitability: 1.4 | Impact: 3.4

Affected Packages2 packages

CVEListV5ibm/i7.2, 7.3, 7.4, 7.5
NVDibm/i4 versions+3

Patches

🔴Vulnerability Details

2
CVEList
IBM i privilege escalation2023-10-15
GHSA
GHSA-7c9p-q9cx-hrg3: IBM Directory Server for IBM i contains a local privilege escalation vulnerability2023-10-15
CVE-2023-40378 (HIGH CVSS 7.8) | IBM Directory Server for IBM i cont | cvebase.io