IBM i 7.2, 7.3, 7.4, and 7.5 is vulnerable to a file level local denial of service caused by an insufficient authority requirement. A local non-privileged user can configure a referential constraint with the privileges of a user socially engineered to access the target file.
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
I | Ibm | 7.2 (including) | 7.2 (including) |
I | Ibm | 7.3 (including) | 7.3 (including) |
I | Ibm | 7.4 (including) | 7.4 (including) |
I | Ibm | 7.5 (including) | 7.5 (including) |