Impact
IBM i versions 7.3 through 7.6 contain a flaw in which an attacker who is locally authenticated can supply a malicious file path that bypasses validation checks. The vulnerability allows the attacker to alter the ownership of arbitrary files on the system, potentially granting them privilege escalation or enabling tampering with critical configuration files.
Affected Systems
Affected products include IBM i releases 7.3, 7.4, 7.5, and 7.6. Users running any of these versions are exposed to the risk; newer supported releases have addressed the issue.
Risk and Exploitability
The flaw drives a CVSS score of 7.8, indicating high severity, and is not listed in CISA's KEV catalog. Exploitation requires a local authenticated session and makes use of an improperly validated file path. Because the attack vector is local and the exploit is straightforward, the risk is significant for any system where users have the ability to interact with the file system. The absence of an EPSS score suggests current exploitation data is limited, but the high CVSS score warrants prompt attention.
OpenCVE Enrichment