Impact
The vulnerability lies in the IBM i Debug Server, where an improperly validated client-supplied profile name allows a remote authenticated attacker to elevate their privileges. This flaw is classified as an Access Control Weakness (CWE-269). By exploiting it, an attacker could gain administrative rights on the system, potentially compromising confidentiality, integrity, and availability of critical data and services.
Affected Systems
Affected systems include IBM i releases 7.6, 7.5, 7.4, and 7.3. The following PTFs fix the issue: SJ10899 for 7.6, SJ10903 for 7.5, SJ10915 for 7.4, and SJ10916 for 7.3. IBM recommends updating to supported, patched versions or applying these specific fix packs.
Risk and Exploitability
The CVSS base score of 8.8 marks this defect as high severity. While the EPSS value is not available, there is no prior evidence that it has been exploited in the wild, and it is not listed in the CISA KEV catalog. The attack requires remote authentication but does not disclose a credential‑less path, so the risk is primarily to systems with valid, possibly weak credentials.
OpenCVE Enrichment