peter bassill · operator
$ cve CVE-2024-51464 JSON

CVE-2024-51464 EXPLOIT

4.3
MEDIUM · CVSS 3.1 · EPSS 1.4% (pctl 72)

Patch early

A public exploit exists.

Description

IBM i 7.3, 7.4, and 7.5 is vulnerable to bypassing Navigator for i interface restrictions. By sending a specially crafted request, an authenticated attacker could exploit this vulnerability to remotely perform operations that the user is not allowed to perform when using Navigator for i.

Scoring

CVSS4.3 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
EPSS1.41% — more likely to be exploited than 72% of all CVEs
WeaknessCWE-288
On CISA KEVno
Public exploityes
Published2024-12-21
Last modified2026-06-17

Affected (1)

VendorProduct
ibmi

Public exploits

SourceTitleDate
exploit-dbIBMi Navigator 7.5 - HTTP Security Token Bypass2025-04-15

References

→ the Explorer  ·  watch your stack  ·  NVD