Impact
IBM i systems running releases 7.3 through 7.6 are vulnerable to an authentication flaw in NTLM session negotiation. An attacker who can reach the NetServer service may cause the system to accept a forged authentication request, thereby gaining access to server resources with the privileges of an authenticated user. This flaw is identified as CWE‑287 and is quantified with a CVSS score of 8.1, indicating a high severity risk of potential full system compromise.
Affected Systems
Affected products include IBM i releases 7.3, 7.4, 7.5, and 7.6. IBM has issued PTFs for each release: MJ10936 for 7.3, MJ10937 for 7.4, MJ10938 for 7.5, and MJ10939 for 7.6, which address the improper authentication issue.
Risk and Exploitability
The CVSS score of 8.1 reflects a significant threat, and although an EPSS score is not available, the lack of an EPSS metric does not indicate absence of exploitation potential. The vulnerability is not listed in the CISA KEV catalog, but the remote nature of the exploit – through the NetServer service – means that any host with network connectivity to the server could potentially leverage the flaw. Immediate application of the relevant PTF or upgrade to a supported release is essential to eliminate this high‑risk authentication bypass.
OpenCVE Enrichment