CVE-2024-51464

IBM i 7.3, 7.4, and 7.5 is vulnerable to bypassing Navigator for i interface restrictions. By sending a specially crafted request, an authenticated attacker could exploit this vulnerability to remotely perform operations that the user is not allowed to perform when using Navigator for i.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:-:*:*:*:*:*:*:*

History

03 Jul 2025, 20:54

Type Values Removed Values Added
CPE cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:-:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
References () https://www.ibm.com/support/pages/node/7179509 - () https://www.ibm.com/support/pages/node/7179509 - Vendor Advisory
References () http://seclists.org/fulldisclosure/2024/Dec/20 - () http://seclists.org/fulldisclosure/2024/Dec/20 - Mailing List
First Time Ibm i
Ibm

31 Dec 2024, 07:15

Type Values Removed Values Added
References
  • () http://seclists.org/fulldisclosure/2024/Dec/20 -
CWE CWE-288

25 Dec 2024, 15:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 4.3
v2 : unknown
v3 : unknown
CWE CWE-644 CWE-288

21 Dec 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-21 14:15

Updated : 2025-07-03 20:54


NVD link : CVE-2024-51464

Mitre link : CVE-2024-51464


JSON object : View

Products Affected

ibm

  • i
CWE

No CWE.