CVE-2024-31870: IBM I

Low severity, CVSS 3.3. EPSS: 0.2% chance of exploitation in the next 30 days.

IBM Db2 for i 7.2, 7.3, 7.4, and 7.5 supplies user defined table function is vulnerable to user enumeration by a local authenticated attacker, without having authority to the related *USRPRF objects. This can be used by a malicious actor to gather information about users that can be targeted in further attacks. IBM X-Force ID: 287174.

Affected products

  • IBM I: version 7.2 only; version 7.3 only; version 7.4 only; version 7.5 only

Published 2024-06-15. Last modified 2026-06-17.