Impact
IBM i 7.6, 7.5, 7.4, and 7.3 are susceptible to a time‑of‑check to time‑of‑use race condition involving symbolic links. The flaw allows a remote authenticated attacker to gain unauthorized access to system objects, potentially enabling read or write operations on protected files. This can lead to privilege escalation or compromise of sensitive data.
Affected Systems
Affected products are IBM i releases 7.6, 7.5, 7.4, and 7.3. The vendor has issued PTF updates – SJ10871 for 7.6, SJ10835 for 7.5, SJ10840 for 7.4, and SJ10841 for 7.3 – which incorporate the fix.
Risk and Exploitability
With a CVSS score of 8.5 the vulnerability is considered high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires remote authenticated access; the attacker must have legitimate credentials to trigger the race condition that allows manipulation of symbolic links to privileged objects. No publicly available exploit information is provided in the data, but the high score and lack of mitigation for non‑patched systems indicate a significant risk.
OpenCVE Enrichment