CVE-2024-22346
NixOS vulnerability analysis and mitigation

Overview

CVE-2024-22346 is a privilege elevation vulnerability affecting Db2 for IBM i versions 7.2, 7.3, 7.4, and 7.5. The vulnerability was discovered and disclosed by IBM, with initial publication on March 14, 2024. The vulnerability stems from an unqualified library call in the Db2 for IBM i infrastructure that could allow local users to gain elevated privileges (IBM Advisory, NVD).

Technical details

The vulnerability is caused by an unqualified library call in the Db2 for IBM i infrastructure. It has been assigned a CVSS v3.1 base score of 7.8 (High) by NVD with the vector string CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, indicating local access, low attack complexity, low privileges required, no user interaction, and high impacts on confidentiality, integrity, and availability. IBM's assessment gives it a slightly higher CVSS score of 8.4 with the vector string CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (NVD).

Impact

A successful exploitation of this vulnerability could allow a malicious actor to cause user-controlled code to run with administrator privileges. This represents a significant security risk as it could lead to complete system compromise through privilege elevation (IBM Advisory).

Exploitability

The vulnerability requires local access to the system for exploitation. No user interaction is needed, and depending on the assessment (NVD vs IBM), either low or no privileges are required to exploit the vulnerability (NVD).

Mitigation and workarounds

IBM has released fixes for all affected versions through PTFs. For IBM i 7.5, users should apply SF99950 (750 Db2 for IBM i Level 6), for 7.4 apply SF99704 (740 Db2 for IBM i Level 27), and for 7.3 and 7.2, multiple individual PTFs are available. No workarounds have been provided, making patch installation the only mitigation option (IBM Advisory).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-68981HIGH8.8
  • NixOS logoNixOS
  • cpe:2.3:a:apache:nifi
NoYesAug 03, 2026
CVE-2026-69153MEDIUM6.3
  • JavaScript logoJavaScript
  • postcss
NoYesAug 03, 2026
CVE-2026-68979MEDIUM5.9
  • NixOS logoNixOS
  • nifi
NoYesAug 03, 2026
CVE-2026-64640MEDIUM5.3
  • Python logoPython
  • polaris
NoYesAug 06, 2026
CVE-2026-68980LOW2.3
  • NixOS logoNixOS
  • apache-nifi
NoYesAug 03, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management