Impact
The vulnerability involves hardcoded cryptographic constants used to obfuscate encryption keys in IBM i versions 7.6, 7.5, 7.4, and 7.3. A remote attacker with authenticated access can exploit this flaw to recover sensitive data, potentially exposing confidential information.
Affected Systems
Affected installations include IBM i 7.6, 7.5, 7.4, and 7.3. The vendor recommends applying PTF SJ11156 for 7.6, SJ11159 for 7.5, SJ11158 for 7.4, and SJ11157 for 7.3, or upgrading to a supported release.
Risk and Exploitability
The impact is classified as moderate with a CVSS score of 4.4. The attack requires remote authenticated access; no publicly known exploit exists, and it is not listed in the KEV catalog. Although the EPSS score is not available, the presence of a known remote authentication vector suggests that organizations using these versions should treat the vulnerability as an actionable risk until the PTF is applied.
OpenCVE Enrichment