CVE-2024-35122

Published Jan 24, 2025

Last updated a month ago

Overview

Description
IBM i 7.2, 7.3, 7.4, and 7.5 is vulnerable to a file level local denial of service caused by an insufficient authority requirement. A local non-privileged user can configure a referential constraint with the privileges of a user socially engineered to access the target file.
Source
psirt@us.ibm.com
NVD status
Received

Risk scores

CVSS 3.1

Type
Primary
Base score
2.8
Impact score
1.4
Exploitability score
1.3
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L
Severity
LOW

Weaknesses

psirt@us.ibm.com
CWE-284

Social media

Hype score
Not currently trending