Impact
The vulnerability is a flaw in the IBM Administration Runtime Expert for i (ARE) GUI component that permits an unauthenticated remote attacker to obtain the privilege level of another authenticated user. By leveraging this weakness the attacker can perform system actions, access, or modify data with the privileges of the compromised user, thereby compromising the integrity, confidentiality, and availability of the IBM i system.
Affected Systems
The flaw affects IBM Administration Runtime Expert for i version 1R1M0 (release 5733‑ARE) deployed on IBM i operating systems. The affected component is the ARE GUI. The recommended fix is the IBM PTF SJ11185, which after installation disables the legacy ARE GUI until the underlying security issue is resolved.
Risk and Exploitability
The vulnerability has a CVSS v3 score of 9.9, classifying it as critical. The EPSS score is unavailable, and it is not listed in the CISA KEV catalog. The attacker does not need prior authentication; based on the description, it is inferred that the attacker may send crafted requests to the ARE GUI component to trigger the privilege escalation. Successful exploitation grants arbitrary elevation to any user profile on the IBM i system, potentially allowing full system compromise. The high severity and lack of detection mechanisms make this a high‑risk vulnerability that warrants immediate remediation.
OpenCVE Enrichment