Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gp43-46q6-g3r3

Опубликовано: 21 нояб. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.7

Описание

IBM i Access Family 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.0 could allow a local authenticated attacker to execute arbitrary code on the system, caused by DLL search order hijacking vulnerability. By placing a specially crafted file in a compromised folder, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 236581.

IBM i Access Family 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.0 could allow a local authenticated attacker to execute arbitrary code on the system, caused by DLL search order hijacking vulnerability. By placing a specially crafted file in a compromised folder, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 236581.

EPSS

Процентиль: 41%
0.00187
Низкий

6.7 Medium

CVSS3

Дефекты

CWE-427

Связанные уязвимости

CVSS3: 7.2
nvd
около 3 лет назад

IBM i Access Family 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.0 could allow a local authenticated attacker to execute arbitrary code on the system, caused by DLL search order hijacking vulnerability. By placing a specially crafted file in a compromised folder, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 236581.

EPSS

Процентиль: 41%
0.00187
Низкий

6.7 Medium

CVSS3

Дефекты

CWE-427