CVE-2023-45185

HIGH

IBM I Access Client Solutions < 1.1.4 - Incorrect Authorization

Title source: rule
STIX 2.1

Description

IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 could allow an attacker to execute remote code. Due to improper authority checks the attacker could perform operations on the PC under the user's authority. IBM X-Force ID: 268273.

Exploits (1)

nomisec WRITEUP
by afine-com · poc
https://github.com/afine-com/CVE-2023-45185

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
https://www.ibm.com/support/pages/node/7091942

Scores

CVSS v3 7.4
EPSS 0.0151
EPSS Percentile 81.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L

Details

CWE
CWE-863
Status published
Products (1)
ibm/i_access_client_solutions 1.1.2 - 1.1.4
Published Dec 14, 2023
Tracked Since Feb 18, 2026