Impact
IBM i systems version 7.3 through 7.6 have a flaw where an authenticated attacker can exploit predictable server seed values to bypass defined security restrictions. The vulnerability allows the attacker to elevate privileges beyond intended levels within the debug server context, potentially accessing or modifying sensitive data or configuration. The flaw is a classic authorization bypass, classified under CWE-330.
Affected Systems
IBM i 7.6, IBM i 7.5, IBM i 7.4, and IBM i 7.3 are impacted. The issue exists in the debug server component of these operating system editions, and only machines running these versions without the appropriate fixes are vulnerable.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate risk. There is no EPSS score available, and the vulnerability has not been listed in the CISA KEV catalog. The attack requires remote authenticated access to the debug server, suggesting that compromised or privileged credentials could be used to exploit the predictable server seeds. If exploited, the attacker can escape the security model imposed by IBM i, potentially impacting confidentiality, integrity, or availability of system data.
OpenCVE Enrichment