First published: Fri Jun 21 2024(Updated: )
IBM i 7.3, 7.4, and 7.5 product IBM TCP/IP Connectivity Utilities for i contains a local privilege escalation vulnerability. A malicious actor with command line access to the host operating system can elevate privileges to gain root access to the host operating system. IBM X-Force ID: 288171.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM OS/400 | <=7.5 | |
IBM OS/400 | <=7.4 | |
IBM OS/400 | <=7.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-31890 is a local privilege escalation vulnerability that can allow a malicious actor to gain root access.
To fix CVE-2024-31890, update your IBM i system to the latest version to close the vulnerability.
CVE-2024-31890 affects IBM i versions 7.3, 7.4, and 7.5.
CVE-2024-31890 requires local command line access to the host operating system for exploitation.
CVE-2024-31890 can allow unauthorized users to escalate their privileges to gain full control over the system.