Impact
The issue is an authentication bypass in IBM i's Navigator for i module that allows a remote attacker to obtain sensitive system information. The vulnerability is classified as CWE-287 and leads to the disclosure of confidential data.
Affected Systems
IBM i releases 7.6, 7.5, 7.4, and 7.3 are affected. Updating the Navigator for i component with the official PTFs—SJ10887 for 7.6, SJ10888 for 7.5, SJ10890 for 7.4, and SJ10891 for 7.3—removes the flaw.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.3, indicating high severity. EPSS data is not available and it is not listed in the CISA KEV catalog. Likely exploitation requires network access to the Navigator for i interface, where the attacker can bypass authentication to read sensitive data. The flaw’s low exploitation complexity increases the risk for exposed systems.
OpenCVE Enrichment