Impact
This vulnerability permits an attacker who is already authenticated to a remote IBM i system to gain higher privileges than intended because the system does not enforce proper privilege boundaries when processing SQL statements. The flaw is a classic privilege escalation weakness identified as CWE-269, and it can compromise confidentiality and integrity of data and potentially lead to full system take‑over if an attacker can execute arbitrary privileged operations.
Affected Systems
IBM i releases 7.6, 7.5, 7.4, and 7.3 are affected. IBM has released public fixes (PTFs) for each release: SJ10823 for 7.6, SJ10822 for 7.5, SJ10821 for 7.4, and SJ10820 for 7.3. Users of unsupported versions are advised to upgrade to a supported, fixed version of IBM i.
Risk and Exploitability
The risk assessment shows a high CVSS score of 8.8 and no KEV listing, indicating that formal exploitation evidence is not yet documented. However, the vulnerability requires only that the attacker holds valid credentials to the SQL subsystem, after which the flaw can be leveraged. Because the exploitation path relies on authenticated access, internal threat actors or compromised user accounts pose the most immediate risk. The EPSS score is unavailable, so a precise probability estimate cannot be given, but the severity suggests that mitigation should not be deferred.
OpenCVE Enrichment