Описание
IBM i 7.4 and 7.5 is vulnerable to an authenticated user gaining elevated privilege to a physical file. A user with authority to a view can alter the based-on physical file security attributes without having object management rights to the physical file. A malicious actor can use the elevated privileges to perform actions restricted by their view privileges.
Ссылки
- Vendor Advisory
Уязвимые конфигурации
Одновременно
Одно из
EPSS
6.8 Medium
CVSS3
Дефекты
Связанные уязвимости
IBM i 7.4 and 7.5 is vulnerable to an authenticated user gaining elevated privilege to a physical file. A user with authority to a view can alter the based-on physical file security attributes without having object management rights to the physical file. A malicious actor can use the elevated privileges to perform actions restricted by their view privileges.
EPSS
6.8 Medium
CVSS3