Impact
The vulnerability in IBM i 7.6, 7.5, 7.4, and 7.3 allows a remote authenticated attacker to execute arbitrary system commands and retrieve sensitive data, yielding full control over the affected system and compromising confidentiality, integrity, and availability. The weakness is a classic privilege escalation flaw as identified by CWE‑250.
Affected Systems
IBM i (v7.3 through v7.6) is affected; the issue has been documented for all releases from 7.3 to 7.6 and manifests when the system is accessed with credentialed users who do not have proper privilege boundaries enforced.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.8, indicating high severity, and, although an EPSS score is not available, the lack of current exploitation records does not diminish the risk of an authenticated attacker exploiting this flaw. The threat is listed as not in the CISA KEV catalog, yet the high CVSS and authority recommendation to address immediately signify that the attack vector—remote authenticated access—poses a significant practical risk to organizations still running these versions.
OpenCVE Enrichment