×

Good News Everybody!

The new search engine is LIVE!

Please report any problems to david (at) midrange.com.




Reading the link provided it mentions "local privilege" and "access to the
command line". I would infer that Management Central code that was still
present, even if the server itself wasn't able to start, was vulnerable.

On Fri, 27 Oct 2023 at 17:00, Rob Berendt <robertowenberendt@xxxxxxxxx>
wrote:

On 7.5 if you try
STRTCPSVR SERVER(*MGTC)
it will abort with
CPF9898: SERVER *MGTC NOT SUPPORTED.

The APAR lists two PTF's. One is to patch MGTC. One is to remove MGTC.

Security Bulletin: IBM i is vulnerable to a local privilege escalation due
to flaws in Management Central (CVE-2023-40685, CVE-2023-40686).
Security Bulletin

https://www.ibm.com/support/pages/node/7060686?myns=swgother&mynp=OCSWG60&mync=E&cm_sp=swgother-_-OCSWG60-_-E
--
This is the Midrange Systems Technical Discussion (MIDRANGE-L) mailing list
To post a message email: MIDRANGE-L@xxxxxxxxxxxxxxxxxx
To subscribe, unsubscribe, or change list options,
visit: https://lists.midrange.com/mailman/listinfo/midrange-l
or email: MIDRANGE-L-request@xxxxxxxxxxxxxxxxxx
Before posting, please take a moment to review the archives
at https://archive.midrange.com/midrange-l.

Please contact support@xxxxxxxxxxxxxxxxxxxx for any subscription related
questions.



As an Amazon Associate we earn from qualifying purchases.

This thread ...

Replies:

Follow On AppleNews
Return to Archive home page | Return to MIDRANGE.COM home page

This mailing list archive is Copyright 1997-2026 by midrange.com and David Gibbs as a compilation work. Use of the archive is restricted to research of a business or technical nature. Any other uses are prohibited. Full details are available on our policy page. If you have questions about this, please contact [javascript protected email address].

Operating expenses for this site are earned using the Amazon Associate program and Google Adsense.