« Volver al listado

CVE-2023-45185

Estado: ModificadaAlta (8.8)—

IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 could allow an attacker to execute remote code. Due to improper authority checks the attacker could perform operations on the PC under the user's authority. IBM X-Force ID: 268273.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-45185",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@us.ibm.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 7.4,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 3.7,
        "exploitabilityScore": 3.1
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@us.ibm.com",
      "affectedData": [
        {
          "vendor": "IBM",
          "product": "i Access Client Solutions",
          "versions": [
            {
              "status": "affected",
              "version": "1.1.2",
              "versionType": "semver",
              "lessThanOrEqual": "1.1.4"
            },
            {
              "status": "affected",
              "version": "1.1.4.3",
              "versionType": "semver",
              "lessThanOrEqual": "1.1.9.3"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-12-14T14:15:42.553",
  "references": [
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/268273",
      "tags": [
        "VDB Entry"
      ],
      "source": "psirt@us.ibm.com"
    },
    {
      "url": "https://www.ibm.com/support/pages/node/7091942",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@us.ibm.com"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/268273",
      "tags": [
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.ibm.com/support/pages/node/7091942",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@us.ibm.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-863"
        }
      ]
    },
    {
      "type": "Secondary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-863"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 could allow an attacker to execute remote code.  Due to improper authority checks the attacker could perform operations on the PC under the user's authority.  IBM X-Force ID:  268273."
    },
    {
      "lang": "es",
      "value": "IBM i Access Client Solutions versiones 1.1.2 a 1.1.4 y 1.1.4.3 a 1.1.9.3 podrían permitir a un atacante ejecutar código remoto. Debido a controles de autoridad inadecuados, el atacante podría realizar operaciones en la PC bajo la autoridad del usuario. ID de IBM X-Force: 268273."
    }
  ],
  "lastModified": "2026-06-17T06:28:23.077",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ibm:i_access_client_solutions:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "531AF116-53A2-47C9-944E-C7E2CA2ADF9B",
              "versionEndIncluding": "1.1.4",
              "versionStartIncluding": "1.1.2"
            },
            {
              "criteria": "cpe:2.3:a:ibm:i_access_client_solutions:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C30A55A7-E0D8-48B0-96A7-7E93B9A14916",
              "versionEndExcluding": "1.1.9.4",
              "versionStartIncluding": "1.1.4.3"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@us.ibm.com"
}