AI analysis
IBM i 7.6, 7.5, 7.4, and 7.3 let a local authenticated user change the ownership of arbitrary files because an attacker-controlled file path is not validated correctly. The attacker must already be signed on to the system; no user interaction is required, and the issue is scoped to the local system. Successful use yields high impact on confidentiality, integrity, and availability (CVSS 3.1 base 7.8), including taking ownership of files the attacker should not control. It affects IBM i installations on those four releases. It is not listed in CISA KEV, and no public proof-of-concept is known.
What to do: Apply the IBM security fix (PTF) for this issue on IBM i 7.3, 7.4, 7.5, and 7.6 as soon as it is available from IBM Fix Central or your vendor bulletin. Until then, limit which local profiles can run the affected function, and review unexpected ownership changes on sensitive objects. This is not remotely exploitable; prioritize systems where many users already have a local sign-on.
Affected
| IBM i | 7.3, 7.4, 7.5, and 7.6 |
Estimated exposure
moderateOn the order of tens of thousands of IBM i systems — IBM i is a specialized enterprise operating system; industry surveys have long put the customer base in the tens of thousands of organizations rather than a mass consumer footprint, and this bug needs an existing local login so internet…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to change the ownership of arbitrary files due to improper validation of an attacker-controlled file path.