CVE-2024-55897
- EPSS 0.04%
- Veröffentlicht 03.01.2025 23:15:08
- Zuletzt bearbeitet 20.06.2025 18:11:09
IBM PowerHA SystemMirror for i 7.4 and 7.5 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user ...
CVE-2024-55896
- EPSS 0.07%
- Veröffentlicht 03.01.2025 23:15:08
- Zuletzt bearbeitet 19.08.2025 13:35:26
IBM PowerHA SystemMirror for i 7.4 and 7.5 contains improper restrictions when rendering content via iFrames. This vulnerability could allow an attacker to gain improper access and perform unauthorized actions on the system.
CVE-2024-31878
- EPSS 0.1%
- Veröffentlicht 07.06.2024 14:15:10
- Zuletzt bearbeitet 21.11.2024 09:14:04
IBM i 7.2, 7.3, 7.4, and 7.5 Service Tools Server (SST) is vulnerable to SST user enumeration by a remote attacker. This vulnerability can be used by a malicious actor to gather information about SST users that can be targeted in further attacks. ...
CVE-2024-27264
- EPSS 0.04%
- Veröffentlicht 22.05.2024 20:15:09
- Zuletzt bearbeitet 30.06.2025 18:15:25
IBM Performance Tools for i 7.2, 7.3, 7.4, and 7.5 could allow a local user to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-controlled code to run with administrator privilege. IBM X-Force ID: 284...
CVE-2024-25050
- EPSS 0.07%
- Veröffentlicht 28.04.2024 13:15:08
- Zuletzt bearbeitet 13.08.2025 13:12:21
IBM i 7.2, 7.3, 7.4, 7.5 and IBM Rational Development Studio for i 7.2, 7.3, 7.4, 7.5 networking and compiler infrastructure could allow a local user to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-c...
CVE-2023-43064
- EPSS 0.03%
- Veröffentlicht 25.12.2023 03:15:08
- Zuletzt bearbeitet 21.11.2024 08:23:39
Facsimile Support for IBM i 7.2, 7.3, 7.4, and 7.5 could allow a local user to gain elevated privileges due to an unqualified library call. A malicious actor could cause arbitrary code to run with the privilege of the user invoking the facsimile sup...
CVE-2023-40685
- EPSS 0.02%
- Veröffentlicht 29.10.2023 02:15:07
- Zuletzt bearbeitet 21.11.2024 08:19:58
Management Central as part of IBM i 7.2, 7.3, 7.4, and 7.5 Navigator contains a local privilege escalation vulnerability. A malicious actor with command line access to the operating system can exploit this vulnerability to elevate privileges to gain...
CVE-2023-40686
- EPSS 0.02%
- Veröffentlicht 29.10.2023 01:15:40
- Zuletzt bearbeitet 21.11.2024 08:19:58
Management Central as part of IBM i 7.2, 7.3, 7.4, and 7.5 Navigator contains a local privilege escalation vulnerability. A malicious actor with command line access to the operating system can exploit this vulnerability to elevate privileges to gain...
CVE-2023-40377
- EPSS 0.03%
- Veröffentlicht 16.10.2023 01:15:09
- Zuletzt bearbeitet 21.11.2024 08:19:19
Backup, Recovery, and Media Services (BRMS) for IBM i 7.2, 7.3, and 7.4 contains a local privilege escalation vulnerability. A malicious actor with command line access to the host operating system can elevate privileges to gain component access to t...
CVE-2023-40378
- EPSS 0.02%
- Veröffentlicht 15.10.2023 02:15:09
- Zuletzt bearbeitet 21.11.2024 08:19:20
IBM Directory Server for IBM i contains a local privilege escalation vulnerability. A malicious actor with command line access to the host operating system can elevate privileges to gain component access to the host operating system. IBM X-Force ID...