Impact
A remote authenticated user can exploit improper privilege management during monitor owner reassignment in IBM i to execute arbitrary commands. The flaw stems from CWE-269, where rights are insufficiently checked when a monitor owner is changed, allowing an attacker to elevate privileges and run commands with the monitor’s authority. Successful exploitation could give the attacker full control over the affected system.
Affected Systems
IBM i operating systems releases 7.3, 7.4, 7.5, and 7.6 are affected.
Risk and Exploitability
The CVSS score of 8.1 classifies this vulnerability as high severity. EPSS data is not available, so the exact exploitation probability cannot be quantified, but the flaw is not listed in the CISA KEV catalog. The attack can be carried out by a remote authenticated user who has the ability to transition monitor ownership, a capability that an attacker could obtain through compromised credentials or abuse of administrative functions.
OpenCVE Enrichment