Impact
A local authenticated attacker who can use SSH on IBM i systems can read privileged files and obtain sensitive information. The vulnerability corresponds to CWE‑267.
Affected Systems
IBM i versions 7.5 and 7.6 are affected. IBM releases a fix as part of Release5733‑SC1, with PTF SJ11404 for 7.6 and PTF SJ11405 for 7.5.
Risk and Exploitability
The CVSS score of 3.3 places the risk in the low range, and an EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog, suggesting limited or no known exploitation. The attack vector requires local authentication; therefore, it cannot be exploited remotely and poses a lower threat to systems without compromised accounts.
OpenCVE Enrichment