CVE-2024-31890: IBM i privilege escalation
IBM i 7.3, 7.4, and 7.5 product IBM TCP/IP Connectivity Utilities for i contains a local privilege escalation vulnerability. A malicious actor with command line access to the host operating system can elevate privileges to gain root access to the host operating system. IBM X-Force ID: 288171.
Other sources
IBM i product IBM TCP/IP Connectivity Utilities for i contains a local privilege escalation vulnerability. A malicious actor with command line access to the host operating system can elevate privileges to gain root access to the host operating system.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-31890?
CVE-2024-31890 is a local privilege escalation vulnerability that can allow a malicious actor to gain root access.
How do I fix CVE-2024-31890?
To fix CVE-2024-31890, update your IBM i system to the latest version to close the vulnerability.
Which versions of IBM i are affected by CVE-2024-31890?
CVE-2024-31890 affects IBM i versions 7.3, 7.4, and 7.5.
Can CVE-2024-31890 be exploited remotely?
CVE-2024-31890 requires local command line access to the host operating system for exploitation.
What impact does CVE-2024-31890 have on systems?
CVE-2024-31890 can allow unauthorized users to escalate their privileges to gain full control over the system.