Impact
IBM i 7.6, 7.5, and 7.4 contain an improper authorization flaw that allows a remote authenticated attacker to alter certain system messages, compromising the integrity of system logging and notifications.
Affected Systems
The vulnerability affects IBM i releases 7.4, 7.5, and 7.6. These releases are addressed by IBM i Release 5770‑SS1. The specific PTFs for each version are SJ11201 for 7.6, SJ11210 for 7.5, and SJ11211 for 7.4.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity. EPSS data is not available, and the vulnerability is not listed in CISA KEV. The attack vector is remote, requiring authentication on the IBM i system, which indicates the need for strong access controls and timely patching.
OpenCVE Enrichment