PT-2025-2429 · Ibm · Ibm I
Published
2025-01-24
·
Updated
2025-09-29
·
CVE-2024-35122
CVSS v3.1
2.8
Low
| Vector | AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions:
IBM i versions 7.2 through 7.5
Description:
The issue is related to a file level local denial of service caused by an insufficient authority requirement. A local non-privileged user can configure a referential constraint with the privileges of a user who has been socially engineered to access the target file.
Recommendations:
For IBM i versions 7.2 through 7.5, consider restricting access to configuring referential constraints to prevent exploitation by local non-privileged users.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Improper Access Control
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ibm I