Impact
The vulnerability arises from improper authentication in IBM i Navigator for i, allowing a remote attacker to bypass authentication and execute arbitrary code or retrieve sensitive data. This weakness, classified as CWE-287, could lead to full system compromise.
Affected Systems
The affected products are IBM i releases 7.3, 7.4, 7.5, and 7.6. IBM provides platform firmware updates (PTFs) to remediate the issue: SJ10887 for 7.6, SJ10888 for 7.5, SJ10890 for 7.4, and SJ10891 for 7.3. No additional version information is provided beyond these releases.
Risk and Exploitability
The CVSS score of 8.3 indicates high severity. EPSS is not available, so no quantified exploitation probability is given, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote exploitation via the Navigator for i service; an attacker needs network access to the system and the ability to interact with the service. This lack of authentication control allows arbitrary code execution and data exposure.
OpenCVE Enrichment