Impact
The vulnerability is a time‑of‑check to time‑of‑use race condition in the SQL query engine of IBM i, which can allow a local attacker to obtain ownership of arbitrary file‑system objects. This enables the attacker to change file ownership or permissions, potentially creating a foothold for further data compromise or denial of service. The weakness corresponds to CWE‑367.
Affected Systems
IBM i versions 7.6, 7.5, 7.4, and 7.3 are affected. The update is available through the IBM i Release5770‑SS1 PTFs: 7.6 developers should install PTFs SJ11015 and SJ11017; 7.5 should install SJ11007; 7.4 should install SJ10970; and 7.3 should install SJ10969.
Risk and Exploitability
The CVSS score of 6 indicates medium impact. Because the flaw requires local system access and is tied to the SQL query engine, the likely attack vector is a local privileged user taking advantage of file‑ownership manipulation. No current exploit is listed in CISA KEV, and the EPSS data is not available, suggesting that exploitation is not commonly observed but remains possible for an attacker with local access. Mitigating the vulnerability by applying the appropriate PTF or upgrading to a supported, fixed release removes the risk.
OpenCVE Enrichment