CVE-2024-22346: IBM i privilege escalation
Db2 for IBM i 7.2, 7.3, 7.4, and 7.5 infrastructure could allow a local user to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-controlled code to run with administrator privilege. IBM X-Force ID: 280203.
Other sources
Db2 for IBM i infrastructure could allow a local user to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-controlled code to run with administrator privilege.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-22346?
The severity of CVE-2024-22346 is rated as critical due to the potential for local users to gain elevated privileges.
How do I fix CVE-2024-22346?
To fix CVE-2024-22346, apply the latest security patches provided by IBM for affected versions of Db2 for IBM i.
Who is affected by CVE-2024-22346?
CVE-2024-22346 affects users of Db2 for IBM i versions 7.2, 7.3, 7.4, and 7.5.
What could a malicious actor do with CVE-2024-22346?
A malicious actor could exploit CVE-2024-22346 to run user-controlled code with administrator privileges.
Is CVE-2024-22346 a remote or local vulnerability?
CVE-2024-22346 is a local vulnerability, meaning it can only be exploited by authenticated local users.