First published: Fri Dec 20 2024(Updated: )
IBM i 7.3, 7.4, and 7.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM OS/400 | <=7.5 | |
IBM OS/400 | <=7.4 | |
IBM OS/400 | <=7.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-51463 has been assigned a high severity rating due to its potential to allow unauthorized access and network enumeration.
To fix CVE-2024-51463, apply the latest patches and updates provided by IBM for your specific IBM i version.
CVE-2024-51463 affects IBM i versions 7.3, 7.4, and 7.5.
CVE-2024-51463 allows an authenticated attacker to perform server-side request forgery (SSRF), which may lead to unauthorized requests being sent from the system.
Yes, CVE-2024-51463 can facilitate network enumeration and potentially other attacks by leveraging SSRF vulnerability.