Impact
The vulnerability is a race condition (CWE‑362) that enables a remote authenticated attacker to obtain sensitive information from IBM i systems by exploiting a timing flaw while accessing the Navigator for i application.
Affected Systems
Affected systems include IBM i Release 7.6, 7.5, 7.4 and 7.3. IBM has issued PTFs for each release – SJ10887 for 7.6, SJ10888 for 7.5, SJ10890 for 7.4 and SJ10891 for 7.3 – that address the race condition.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and the EPSS score is not available, so the likelihood of exploitation is uncertain. The vulnerability is not listed in CISA KEV. The likely attack vector is a remote authenticated action that requires precise timing and access to privileged operations within Navigator for i. While the race condition may elevate the technical barrier to exploitation, the potential for sensitive data disclosure justifies prompt remediation.
OpenCVE Enrichment