Impact
IBM i 7.6, 7.5, 7.4, and 7.3 contain a race condition in the Navigator for i component that allows a remote authenticated attacker to obtain sensitive information and bypass security restrictions.
Affected Systems
Affected systems are IBM i Release 5770‑SS1 Option 3 for versions 7.6, 7.5, 7.4, and 7.3. IBM issued PTFs SJ10887 (for 7.6), SJ10888 (for 7.5), SJ10890 (for 7.4), and SJ10891 (for 7.3) to remediate the issue. Users must install the appropriate PTF or upgrade to a supported, patched release.
Risk and Exploitability
The CVSS score is 6.3, indicating medium severity. No EPSS score is provided, so the current exploitation probability cannot be quantified. The vulnerability is not listed in CISA KEV. The attack vector is remote authenticated; an attacker requires valid credentials to exploit the race condition and obtain privileged information.
OpenCVE Enrichment