CVE-2024-38330: IBM i privilege escalation
IBM System Management for i 7.2, 7.3, and 7.4 could allow a local user to gain elevated privileges due to an unqualified library program call. A malicious actor could cause user-controlled code to run with administrator privilege. IBM X-Force ID: 295227.
Other sources
IBM System Management for i could allow a local user to gain elevated privileges due to an unqualified library program call. A malicious actor could cause user-controlled code to run with administrator privilege.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-38330?
The severity of CVE-2024-38330 is considered high due to the potential for local users to gain elevated privileges.
How do I fix CVE-2024-38330?
To fix CVE-2024-38330, users should apply the latest security updates provided by IBM for systems running affected versions.
Who is affected by CVE-2024-38330?
CVE-2024-38330 affects IBM System Management for i versions 7.2, 7.3, and 7.4.
What kind of exploit is associated with CVE-2024-38330?
CVE-2024-38330 allows a malicious actor to execute user-controlled code with administrator privileges.
Is there a workaround for CVE-2024-38330?
Currently, the best approach is to update the affected systems, as no official workaround has been provided for CVE-2024-38330.