IBM i2 Analyst Notebook 9.2.0 and 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://www.ibm.com/support/pages/node/6356497 | patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/187874 | vdb entry vendor advisory |