Impact
The vulnerability stems from unsafe reflection in IBM i Navigator for i, permitting a remote authenticated attacker to bypass security restrictions. This flaw maps to CWE‑915 and can lead to unauthorized access or elevated privileges within the system, potentially compromising data confidentiality and integrity.
Affected Systems
Affected versions include IBM i 7.3, 7.4, 7.5, and 7.6. Patches are available as PTF SJ10891 for 7.3, SJ10890 for 7.4, SJ10888 for 7.5, and SJ10887 for 7.6. IBM advises users of unsupported versions to upgrade to a supported and fixed release.
Risk and Exploitability
The CVSS score of 8.3 indicates a high severity vulnerability. EPSS is not available, so the exploitation probability cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. The attack requires remote authenticated access, and the unsafe reflection mechanism can be leveraged to defeat security controls if the vulnerability remains unpatched.
OpenCVE Enrichment