Impact
The vulnerability allows a locally authenticated attacker to change the ownership of arbitrary files on IBM i systems due to improper validation of an attacker‑controlled file path. This flaw falls under an incorrect permission assignment and could enable the attacker to gain additional privileges, modify sensitive files or data, and compromise the integrity of the system. The description does not indicate any remote or network‑level exploitation, so the impact is limited to local users with sufficient authentication.
Affected Systems
IBM i versions 7.6, 7.5, 7.4, and 7.3 are affected. The vendor provides specific patch notes for each release, and the official remedy is to apply the corresponding IBM i Release5770‑SS1 update or the release‑specific PTFs (SJ11607 for 7.6, SJ11608 for 7.5, SJ11609 for 7.4, and SJ11610 for 7.3).
Risk and Exploitability
The CVSS score of 7.8 classifies the issue as High severity. EPSS information is not available, so exploitation probability cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a local authenticated user who can choose file paths; there is no indication of exploitation across a network or via a remote service. The risk is consequently high within systems that allow local authentication, but it does not extend to remote attackers.
OpenCVE Enrichment