Impact
An IBM i vulnerability grants an authenticated attacker the ability to read sensitive information about processes in the PASE environment. The flaw allows the attacker to access data on processes they are not permitted to view, exposing potential confidentiality risks. The issue is identified as an instance of sensitive information exposure (CWE-200), indicating that protected data can be disclosed to unauthorized users once authentication is achieved. Lack of publicly reported exploits and the absence of an EPSS score suggest limited known exploitation, and the vulnerability is not listed in CISA's KEV catalog. The CVSS score of 6.5 indicates a moderate severity, and exploitation requires the attacker to have authenticated credentials on the IBM i system, implying that the threat is primarily to users with existing access rights rather than to unauthenticated remote attackers.
Affected Systems
IBM i releases 7.3, 7.4, 7.5 and 7.6 are affected. Each version can be patched using the specific Platform Technical Fix (PTF) numbers: 7.6 requires PTF MJ11365, 7.5 requires MJ11364, 7.4 requires MJ11363, and 7.3 requires MJ11362. Upgrading to IBM i Release5770-999, which includes the fix, is also a viable path for all affected releases.
Risk and Exploitability
With a CVSS base score of 6.5, the vulnerability presents a moderate risk level. The lack of a documented EPSS score and the fact that it is not flagged in KEV imply that no widespread exploitation has been observed. Because the described attack requires authentication and the specific vector (local or remote) is not detailed in the advisory, the most evident risk is to users who already have privileged or valid user credentials on the IBM i platform.
OpenCVE Enrichment