Impact
The vulnerability in IBM i 7.3 through 7.6 allows a remote attacker to supply a client‑asserted identity that is incorrectly validated by the system. By doing so, the attacker can impersonate a higher‑privileged user, thereby bypassing authentication checks and gaining unauthorized access to services and resources on the IBM i platform. This flaw is classified as CWE‑287, indicating a security logic vulnerability where authentication or authorization checks are inadequate.
Affected Systems
IBM i Release 5770‑SS1 running versions 7.6, 7.5, 7.4, and 7.3 are affected. The advisory lists specific Program Temporary Fixes (PTFs) for each release: for 7.6 the relevant PTFs are SJ11101, SJ11097, SJ11098, SJ11099, and SJ11102; for 7.5 the PTFs are SJ11101, SJ11097, SJ11098; for 7.4 the same set of PTFs applies; and for 7.3 the applicable PTF is SJ11101, SJ11097. Services impacted are Host Servers, Debug Server, Telnet, and DRDA/DDM.
Risk and Exploitability
The flaw carries a CVSS score of 8.1, indicating high severity. EPSS data is not available and the vulnerability is not listed in CISA’s KEV catalog, suggesting that widespread exploitation is not confirmed yet. The attack vector is remote, relying on network connections to the affected services. Should an attacker successfully bypass the identity validation, they could gain unauthorized control or access, potentially compromising confidentiality, integrity, or availability of the IBM i system.
OpenCVE Enrichment