Impact
The vulnerability allows a remote authenticated attacker to bypass security restrictions due to improper authorization in IBM i. The flaw is classified as CWE-285, indicating that the system fails to enforce correct authorization checks, potentially letting an attacker elevate privileges or access protected resources beyond intended permissions.
Affected Systems
Affected products are IBM i versions 7.6, 7.5, 7.4, and 7.3. The corresponding IBM PTFs to remediate the flaw are SJ10887 for 7.6, SJ10888 for 7.5, SJ10890 for 7.4, and SJ10891 for 7.3. All identified CPEs reflect these versions.
Risk and Exploitability
The CVSS score of 4.3 reflects a moderate impact. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves a remote authenticated user exploiting the lack of proper authorization checks, which could allow unauthorized privilege escalation or data access if not mitigated promptly.
OpenCVE Enrichment