Impact
An improper validation of attacker‑supplied user profile names in IBM i enables a remote authenticated attacker to bypass security restrictions, potentially granting unauthorized privileges. The flaw is linked to CWE‑250, where code fails to restrict the use of privileged credentials. An attacker who can supply a crafted profile name may therefore execute elevated operations or access protected data that should be restricted.
Affected Systems
IBM i versions 7.6, 7.5, 7.4, and 7.3 are affected. The recommended fixes are the PTFs SJ10878 for 7.6, SJ10917 for 7.5, SJ10934 for 7.4, and SJ10935 for 7.3. IBM advises that users on unsupported releases upgrade to a supported and fixed version.
Risk and Exploitability
The CVSS v3 score is 8.2, indicating high severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote authenticated connection, where the attacker crafts a user profile name that bypasses validation. No additional prerequisites beyond authentication are noted in the description, so the vulnerability appears readily exploitable if the affected service is reachable.
OpenCVE Enrichment