CVE-2023-37410: IBM Person Communications
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
IBM Personal Communications 14.05, 14.06, and 15.0.0 could allow a local user to escalate their privileges to the SYSTEM user due to overly permissive access controls. IBM X-Force ID: 260138.
Affected products
- IBM Person Communications: version 14.0.5 only; version 14.0.6 only; version 15.0.0 only
Published 2023-09-20. Last modified 2026-06-17.