CVE-2024-55898

IBM i 7.2, 7.3, 7.4, and 7.5 could allow a user with the capability to compile or restore a program to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-controlled code to run with administrator privilege.
References
Link Resource
https://www.ibm.com/support/pages/node/7183835 Vendor Advisory
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:ibm:i:7.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:-:*:*:*:*:*:*:*

History

03 Jul 2025, 20:52

Type Values Removed Values Added
First Time Ibm
Ibm i
References () https://www.ibm.com/support/pages/node/7183835 - () https://www.ibm.com/support/pages/node/7183835 - Vendor Advisory
CPE cpe:2.3:o:ibm:i:-:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
Summary
  • (es) IBM i 7.2, 7.3, 7.4 y 7.5 podría permitir que un usuario con la capacidad de compilar o restaurar un programa obtenga privilegios elevados debido a una llamada a una librería no calificada. Un actor malintencionado podría provocar que el código controlado por el usuario se ejecute con privilegios de administrador.

24 Feb 2025, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-24 02:15

Updated : 2025-07-03 20:52


NVD link : CVE-2024-55898

Mitre link : CVE-2024-55898

CVE.ORG link : CVE-2024-55898


JSON object : View

Products Affected

ibm

  • i
CWE
CWE-427

Uncontrolled Search Path Element