CVE-2023-23470: IBM i privilege escalation
IBM i 7.2, 7.3, 7.4, and 7.5 could allow an authenticated privileged administrator to gain elevated privileges in non-default configurations, as a result of improper SQL processing. By using a specially crafted SQL operation, the administrator could exploit the vulnerability to perform additional administrator operations. IBM X-Force ID: 244510.
Other sources
IBM i could allow an authenticated privileged administrator to gain elevated privileges in non-default configurations, as a result of improper SQL processing. By using a specially crafted SQL operation, the administrator could exploit the vulnerability to perform additional administrator operations.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-23470?
The severity of CVE-2023-23470 is high with a value of 7.2.
How does CVE-2023-23470 affect IBM i?
CVE-2023-23470 affects IBM i versions 7.2, 7.3, 7.4, and 7.5.
What is the risk of privilege escalation in CVE-2023-23470?
CVE-2023-23470 allows an authenticated privileged administrator to gain elevated privileges in certain configurations.
How can an attacker exploit CVE-2023-23470?
An attacker can exploit CVE-2023-23470 by using a specially crafted SQL operation.
Is there a fix available for CVE-2023-23470?
Yes, IBM has provided a fix for CVE-2023-23470. Please refer to the IBM Support Page for instructions.