Impact
The vulnerability arises from improper enforcement of authentication controls, allowing a remote authenticated attacker to bypass expected checks and gain access to sensitive information. Because the flaw enables an attacker who can present credentials to obtain data that should be restricted, the impact includes exposure of confidential data and the potential to exploit elevated privileges for further attacks on the system. The weakness is identified as a classic authentication bypass (CWE‑287).
Affected Systems
IBM Administration Runtime Expert for i on the IBM i platform, specifically the 1R1M0 release. This version is known to lack the necessary authentication enforcement that protects sensitive data and privileged operations.
Risk and Exploitability
The base score for this vulnerability is 7.5, indicating a high severity level. EPSS is not provided, and the vulnerability is not listed in the CISA KEV catalog. The likely attack path involves a remote authenticated attacker leveraging user credentials or compromised accounts to exploit the denial of proper authentication. Because the flaw requires the attacker to be authenticated, mitigation is most effective by removing the vulnerability through the defined PTF rather than relying on generic monitoring or access controls alone.
OpenCVE Enrichment