IBM i 7.3, 7.4, and 7.5 is vulnerable to bypassing Navigator for i interface restrictions. By sending a specially crafted request, an authenticated attacker could exploit this vulnerability to remotely perform operations that the user is not allowed to perform when using Navigator for i.
CVSS
No CVSS.
References
Link | Resource |
---|---|
http://seclists.org/fulldisclosure/2024/Dec/20 | Mailing List |
https://www.ibm.com/support/pages/node/7179509 | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
03 Jul 2025, 20:54
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:* cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:* cpe:2.3:o:ibm:i:-:*:*:*:*:*:*:* cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:* |
|
References | () https://www.ibm.com/support/pages/node/7179509 - Vendor Advisory | |
References | () http://seclists.org/fulldisclosure/2024/Dec/20 - Mailing List | |
First Time |
Ibm i
Ibm |
31 Dec 2024, 07:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
CWE |
25 Dec 2024, 15:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : unknown |
CWE | CWE-288 |
21 Dec 2024, 14:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-12-21 14:15
Updated : 2025-07-03 20:54
NVD link : CVE-2024-51464
Mitre link : CVE-2024-51464
JSON object : View
Products Affected
ibm
- i
CWE
No CWE.