Impact
The vulnerability allows a remote authenticated attacker to gain higher privileges due to improper authorization when handling high‑authority threads. The flaw could enable the attacker to execute functions with elevated rights, potentially leading to full system compromise. The weakness is classified as CWE‑269.
Affected Systems
Affected IBM i releases include 7.6, 7.5, 7.4, and 7.3. For version 7.6 the fix is available as PTF SJ10887, for 7.5 as SJ10888, for 7.4 as SJ10890, and for 7.3 as SJ10891. Systems should ensure they apply the corresponding patch or upgrade to a supported release that includes the fix.
Risk and Exploitability
The CVSS v3.1 base score is 9.6, indicating a critical severity. The EPSS score is not available, but the lack of a KEV listing does not reduce the risk; a remote authenticated attacker can exploit the flaw. Proper remediation is essential to prevent attackers from escalating privileges on the system.
OpenCVE Enrichment