Spooky New Security Vulns Lurking on IBM i
November 1, 2023 Alex Woodie
Halloween has come and gone, but the scares will stick around for a while for IBM i administrators, who have been given more than a dozen fixes by IBM to address some pretty serious security vulnerabilities recently revealed in the heart of the operating system, including in spooky old friends Java and OpenSSL.
On October 27, IBM issued a security bulletin for two CVEs, including CVE-2023-40685 and CVE-2023-40686, which describe two separate but related security flaws in the Management Central component of IBM i Navigator in IBM i versions 7.2 through 7.5.
The first privilege escalation vulnerability, CVE-2023-40685, could …
Read more