Impact
IBM i versions 7.6, 7.5, 7.4, and 7.3 contain a flaw that allows a remote attacker to bypass security restrictions by providing improperly validated user-controlled addresses. This vulnerability is an instance of improper authorization (CWE-269). The flaw can potentially allow the attacker to gain higher privileges or execute arbitrary code within the affected IBM i environment, compromising confidentiality, integrity, and availability of the system.
Affected Systems
Affected systems include IBM i Release 7.6, 7.5, 7.4, and 7.3. Specific PTFs addressed by IBM for each release are: for 7.6 – SJ11037, SJ11013, SJ11065, SJ11078; for 7.5 – SJ10990, SJ11014, SJ11042, SJ11066, SJ11080; for 7.4 – SJ11016, SJ11041, SJ11064, SJ11081; for 7.3 – SJ11040, SJ11063, SJ11079. Users should ensure their IBM i installations are updated with these patches to eliminate the vulnerability.
Risk and Exploitability
The vulnerability scores a CVSS of 8.9, indicating high severity, and it is not listed in the CISA KEV catalog, but the EPSS score is not available, suggesting limited public exploitation data. Nevertheless, the flaw permits a remote attacker to influence the system by feeding crafted addresses that bypass security checks. Attackers would need network access to the IBM i system and could exploit the vulnerability through exposed services that accept address input, potentially leading to privilege escalation or arbitrary code execution. Given the high CVSS and the lack of existing mitigation, the risk remains significant.
OpenCVE Enrichment