Impact
IBM i 7.6, 7.5, 7.4, and 7.3 contain a flaw that allows a remote authenticated attacker to bypass security restrictions by escalating privileges. The vulnerability stems from improper privilege management and enables the attacker to gain higher levels of access than authorized, potentially revealing or modifying protected data and system configuration.
Affected Systems
The affected system is IBM i for versions 7.3, 7.4, 7.5, and 7.6. Each version can be identified by its major release number and may be updated using the corresponding PTFs listed in the advisory.
Risk and Exploitability
The CVSS score of 3.1 indicates a low severity overall, and no exploit probability has been published in EPSS. The vulnerability is not currently listed in CISA’s KEV catalog. The attack requires a valid authenticated session to IBM i, and the attacker must possess at least basic user privileges. Once authenticated, the attacker can exploit the privilege escalation to assume higher rights, potentially leading to unauthorized access to sensitive information or system control if combined with other weaknesses.
OpenCVE Enrichment