CVE-2024-51464

IBM i 7.3, 7.4, and 7.5 is vulnerable to bypassing Navigator for i interface restrictions. By sending a specially crafted request, an authenticated attacker could exploit this vulnerability to remotely perform operations that the user is not allowed to perform when using Navigator for i.
Configurations

No configuration.

History

31 Dec 2024, 07:15

Type Values Removed Values Added
References
  • () http://seclists.org/fulldisclosure/2024/Dec/20 -

25 Dec 2024, 15:15

Type Values Removed Values Added
CWE CWE-644 CWE-288
Summary
  • (es) IBM i 7.3, 7.4 y 7.5 es vulnerable a la omisión de las restricciones de la interfaz de Navigator for i. Al enviar una solicitud especialmente manipulada, un atacante autenticado podría aprovechar esta vulnerabilidad para realizar de forma remota operaciones que el usuario no tiene permitido realizar cuando utiliza Navigator for i.

21 Dec 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-21 14:15

Updated : 2024-12-31 07:15


NVD link : CVE-2024-51464

Mitre link : CVE-2024-51464

CVE.ORG link : CVE-2024-51464


JSON object : View

Products Affected

No product.

CWE
CWE-288

Authentication Bypass Using an Alternate Path or Channel