Impact
IBM i systems running versions 7.6, 7.5, 7.4, and 7.3 on the LDAP interface can suffer from improper privilege management. This flaw enables a local attacker with sufficient access to the system to read sensitive data or modify protected objects. The weakness stems from a failure to correctly enforce access controls, categorized as CWE-269. The resulting damage includes confidentiality and integrity breaches, potentially allowing data exfiltration or unauthorized system changes.
Affected Systems
Affected vendor and product are IBM i. The affected versions are 7.6, 7.5, 7.4, and 7.3, as identified in the Industrial-grade CPE references. Any installation of these versions that interfaces with LDAP is considered vulnerable.
Risk and Exploitability
The CVSS score of 4.4 indicates a moderate risk, but the lack of an available EPSS score and absence from the CISA KEV catalog suggest that exploitation is not widely observed or documented. The flaw is exploitable only from a local context, requiring the attacker to already have some presence on the affected IBM i system. No public exploit code is known, and the vulnerability does not expose remote capabilities. Therefore, while the impact is significant for users with local administrative access, the likelihood of a widespread active compromise remains low at present.
OpenCVE Enrichment