Impact
The vulnerability is a path traversal flaw in IBM i released versions 7.6, 7.5, 7.4 and 7.3 that permits a remote authenticated attacker to reference arbitrary objects, thereby exposing sensitive data or allowing modification of objects. The flaw falls under CWE‑22 and directly jeopardizes confidentiality and integrity for users with authenticated credentials.
Affected Systems
Affected systems are IBM i releases 7.3, 7.4, 7.5 and 7.6. IBM provides specific PTFs for each: SJ10841 for 7.3, SJ10840 for 7.4, SJ10835 for 7.5 and SJ10871 for 7.6.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity. EPSS data is not available, and the vulnerability is not listed in CISA KEV, implying no known mass exploitation. Attack requires valid credentials, so the threat surface is limited to users with privileged access, but the impact of gaining object access remains significant.
OpenCVE Enrichment