CVE-2024-25050

CWE-4273 documents3 sources
Severity
7.8HIGH
EPSS
0.1%
top 78.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 28

Description

IBM i 7.2, 7.3, 7.4, 7.5 and IBM Rational Development Studio for i 7.2, 7.3, 7.4, 7.5 networking and compiler infrastructure could allow a local user to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-controlled code to run with administrator privileges. IBM X-Force ID: 283242.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.5 | Impact: 5.9

Affected Packages4 packages

CVEListV5ibm/rational_development_studio_for_i7.2, 7.3, 7.4, 7.5
NVDibm/rational_developer4 versions+3
CVEListV5ibm/i7.2, 7.3, 7.4, 7.5
NVDibm/i4 versions+3

🔴Vulnerability Details

2
CVEList
IBM i privilege escalation2024-04-28
GHSA
GHSA-548g-3cxj-m7m4: IBM i 72024-04-28
CVE-2024-25050 (HIGH CVSS 7.8) | IBM i 7.2 | cvebase.io