Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-42861 | IBM i 7.4 and 7.5 is vulnerable to an authenticated user gaining elevated privilege to a physical file. A user with authority to a view can alter the based-on physical file security attributes without having object management rights to the physical file. A malicious actor can use the elevated privileges to perform actions restricted by their view privileges. |
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7179158 |
|
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 03 Jul 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:o:ibm:i:-:*:*:*:*:*:*:* |
Wed, 18 Dec 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 18 Dec 2024 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM i 7.4 and 7.5 is vulnerable to an authenticated user gaining elevated privilege to a physical file. A user with authority to a view can alter the based-on physical file security attributes without having object management rights to the physical file. A malicious actor can use the elevated privileges to perform actions restricted by their view privileges. | |
| Title | IBM i incorrect privilege assignment | |
| First Time appeared |
Ibm
Ibm i |
|
| Weaknesses | CWE-732 | |
| CPEs | cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:* cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm i |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2024-12-18T14:41:39.925Z
Reserved: 2024-09-18T19:26:44.571Z
Link: CVE-2024-47104
Updated: 2024-12-18T14:41:31.479Z
Status : Analyzed
Published: 2024-12-18T11:15:05.763
Modified: 2025-07-03T20:54:13.533
Link: CVE-2024-47104
No data.
OpenCVE Enrichment
No data.
EUVD