IBM i 7.6 contains a privilege escalation vulnerability due to incorrect profile swapping in an OS command. A malicious actor can use the command to elevate privileges to gain root access to the host operating system.
A product inherits a set of insecure permissions for an object, e.g. when copying from an archive file, without user awareness or involvement.
Link | Tags |
---|---|
https://www.ibm.com/support/pages/node/7231025 | vendor advisory |