CVE-2023-40685: IBM i privilege escalation
Management Central as part of IBM i 7.2, 7.3, 7.4, and 7.5 Navigator contains a local privilege escalation vulnerability. A malicious actor with command line access to the operating system can exploit this vulnerability to elevate privileges to gain root access to the operating system. IBM X-Force ID: 264116.
Other sources
Management Central as part of IBM i Navigator contains a local privilege escalation vulnerability. A malicious actor with command line access to the operating system can exploit this vulnerability to elevate privileges to gain root access to the operating system.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-40685?
CVE-2023-40685 is a local privilege escalation vulnerability in IBM i Management Central.
What is the severity of CVE-2023-40685?
CVE-2023-40685 has a severity level of high.
How does CVE-2023-40685 affect IBM i?
CVE-2023-40685 affects IBM i versions 7.2, 7.3, 7.4, and 7.5.
How can a malicious actor exploit CVE-2023-40685?
A malicious actor with command line access to the operating system can exploit CVE-2023-40685 to gain root access and elevate privileges on IBM i.
Is there a fix available for CVE-2023-40685?
Yes, IBM has provided a fix for CVE-2023-40685. Please refer to the IBM support page for details.