Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f74p-mfvv-mm55

Опубликовано: 08 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.1

Описание

IBM i 7.3, 7.4, 7.5, and 7.6 is affected by an authenticated user obtaining elevated privileges with IBM Digital Certificate Manager for i (DCM) due to a web session hijacking vulnerability. An authenticated user without administrator privileges could exploit this vulnerability to perform actions in DCM as an administrator.

IBM i 7.3, 7.4, 7.5, and 7.6 is affected by an authenticated user obtaining elevated privileges with IBM Digital Certificate Manager for i (DCM) due to a web session hijacking vulnerability. An authenticated user without administrator privileges could exploit this vulnerability to perform actions in DCM as an administrator.

EPSS

Процентиль: 5%
0.0002
Низкий

7.1 High

CVSS3

Дефекты

CWE-290

Связанные уязвимости

CVSS3: 7.1
nvd
6 месяцев назад

IBM i 7.3, 7.4, 7.5, and 7.6 is affected by an authenticated user obtaining elevated privileges with IBM Digital Certificate Manager for i (DCM) due to a web session hijacking vulnerability. An authenticated user without administrator privileges could exploit this vulnerability to perform actions in DCM as an administrator.

CVSS3: 7.1
fstec
6 месяцев назад

Уязвимость операционной системы IBM i, связанная с обходом аутентификации посредством спуфинга, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 5%
0.0002
Низкий

7.1 High

CVSS3

Дефекты

CWE-290