CVE-2024-22318
- EPSS 0.14%
- Veröffentlicht 09.02.2024 01:15:09
- Zuletzt bearbeitet 21.11.2024 08:56:03
IBM i Access Client Solutions (ACS) 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.4 is vulnerable to NT LAN Manager (NTLM) hash disclosure by an attacker modifying UNC capable paths within ACS configuration files to point to a hostile server. If NTLM...
CVE-2023-45182
- EPSS 0.63%
- Veröffentlicht 14.12.2023 14:15:42
- Zuletzt bearbeitet 21.11.2024 08:26:29
IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 is vulnerable to having its key for an encrypted password decoded. By somehow gaining access to the encrypted password, a local attacker could exploit this vulnerability t...
CVE-2023-45185
- EPSS 1.51%
- Veröffentlicht 14.12.2023 14:15:42
- Zuletzt bearbeitet 21.11.2024 08:26:30
IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 could allow an attacker to execute remote code. Due to improper authority checks the attacker could perform operations on the PC under the user's authority. IBM X-Force I...
CVE-2023-45184
- EPSS 5.1%
- Veröffentlicht 14.12.2023 02:15:12
- Zuletzt bearbeitet 21.11.2024 08:26:30
IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 could allow an attacker to obtain a decryption key due to improper authority checks. IBM X-Force ID: 268270.
CVE-2022-40746
- EPSS 0.08%
- Veröffentlicht 21.11.2022 18:15:14
- Zuletzt bearbeitet 21.11.2024 07:21:58
IBM i Access Family 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.0 could allow a local authenticated attacker to execute arbitrary code on the system, caused by DLL search order hijacking vulnerability. By placing a specially crafted file in a compr...