Impact
A local attacker can increase their privileges on IBM i systems by exploiting improper privilege management (CWE-269) in the HTTP Server component. The flaw allows the attacker to gain elevated rights that can be used to execute arbitrary actions affecting the confidentiality and integrity of the system.
Affected Systems
IBM i releases 7.3, 7.4, 7.5 and 7.6 are affected. The recommended PTFs are SJ11138 for 7.3, SJ11137 for 7.4, SJ11136 for 7.5 and SJ11135 for 7.6. These patches address the improper privilege handling.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity issue. Because exploitation requires local access, the likelihood of attack depends on the presence of a threat actor with physical or local network access. The vulnerability is not currently listed in the CISA KEV catalog and no EPSS value is available, so the exact exploitation probability is uncertain, but the potential for severe impact warrants prompt remediation.
OpenCVE Enrichment