Impact
The flaw is a time‑of‑check to time‑of‑use race condition in the SQL query engine of IBM i, affecting versions 7.3 through 7.6. The vulnerability allows a local attacker to change the ownership of arbitrary file‑system objects, which can be leveraged to gain higher privileges, modify or delete data, or disrupt service availability. This corresponds to CWE‑367. The impact is limited to local users but can result in system‑wide compromise if the corrupted ownership grants administrative access.
Affected Systems
IBM i 7.3, 7.4, 7.5, and 7.6 are affected. The affected vendors and product are IBM and IBM i respectively.
Risk and Exploitability
The CVSS score of 6 renders the vulnerability medium severity, while the EPSS score of less than 1% indicates that exploitation events are infrequent. The issue is not listed in CISA’s KEV catalog, suggesting that no widespread, documented exploitation is known. Attackers must first gain local system access to the target IBM i instance and then trigger the SQL query engine in a manner that creates the TOCTOU condition. Once the race is resolved, ownership hijack of file‑system objects may occur, potentially enabling privilege escalation or denial of service. The vulnerability’s exploitability is constrained by the need for local access, but in environments with many local users the risk should still be considered significant.
OpenCVE Enrichment