Impact
A local authenticated attacker can leverage a flaw in the Navigator for i debugger to elevate privileges on IBM i 7.3, 7.4, 7.5, and 7.6 systems. The vulnerability allows the attacker to access or manipulate sensitive data and to create profiles with elevated privileges, compromising confidentiality, integrity, and overall system security. The weakness is an access control flaw (CWE‑285).
Affected Systems
IBM i Release 7.3, 7.4, 7.5, and 7.6 are affected. The flaw exists in the Navigator for i debugger component of these releases.
Risk and Exploitability
The CVSS score of 8.2 indicates a high severity of this privilege escalation. The EPSS score is not available, so the current exploitation probability is unknown, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a local authenticated user with inappropriate access to the debugger. If the flaw is exploited, the attacker can gain elevated privileges and potentially compromise all data and processes on the IBM i system.
OpenCVE Enrichment