Impact
The vulnerability is a time‑of‑check to time‑of‑use race condition in IBM i’s Network Authentication Service that permits an attacker who is locally authenticated to gain unauthorized access to protected files. This flaw can lead to confidentiality violations by allowing reading, altering, or executing files that the attacker should not have permission to access. The weakness is identified as CWE‑367.
Affected Systems
IBM i versions 7.3, 7.4, 7.5, and 7.6 are vulnerable. The affected components are the Network Authentication Service policies and file access control routines. Only supported releases of IBM i are corrected by forthcoming Release5770‑SS1 patch and corresponding PTFs for each platform.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, while the EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog. The attack requires local authenticated access, meaning it is primarily exploitable by users who already have system login credentials. The race condition in the service’s file access checks can be triggered without additional privilege escalation, making it a serious risk for systems where users have higher‑than‑necessary file permissions and where the IBM i patches are not yet applied.
OpenCVE Enrichment