Impact
The vulnerability is caused by an interpretation conflict in the multipart parser of IBM i, representing a CWE‑436 weakness in access control. This flaw allows a remote authenticated attacker to bypass security restrictions. It does not provide arbitrary code execution but undermines the integrity of the system’s access controls, potentially allowing an attacker to execute actions beyond their authorized privileges.
Affected Systems
IBM i versions 7.3 through 7.6 are affected. The specific patch numbers depend on the release: SJ10887 for 7.6, SJ10888 for 7.5, SJ10890 for 7.4, and SJ10891 for 7.3. Unsupported or older versions should be upgraded to a supported and fixed version.
Risk and Exploitability
The CVSS score is 3, indicating a low overall severity. EPSS data is unavailable and the vulnerability is not listed in the KEV catalog. The attack requires remote authenticated access, implying that valid credentials are necessary. Although the risk of exploitation is low, the bypass of security restrictions can still facilitate further compromise in a broader attack scenario.
OpenCVE Enrichment