IBM i Access Client Solutions
Description
IBM i Access Client Solutions 1.1.2-1.1.9.3 allows a local attacker to retrieve the password decryption key due to improper authority checks.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
IBM i Access Client Solutions 1.1.2-1.1.9.3 allows a local attacker to retrieve the password decryption key due to improper authority checks.
Vulnerability
IBM i Access Client Solutions (ACS) versions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 contain a vulnerability in their password storage mechanism. The application fails to perform proper authority checks when accessing the decryption key used to protect stored passwords. This allows a local user who can run ACS to retrieve the key, compromising the confidentiality of encrypted passwords.
Exploitation
An attacker must have local access to the system running the affected version of IBM i Access Client Solutions. No authentication is required beyond the ability to launch the application. The attacker can exploit the weak authority checks to directly obtain the decryption key from the application's storage.
Impact
Successful exploitation allows the attacker to retrieve the decryption key. If they also have access to the encrypted password data (e.g., via another vulnerability or physical access), they can decrypt passwords used to access other IBM i systems. This leads to a high impact on confidentiality of those systems. The CVSS vector (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) reflects a high confidentiality impact but no direct impact on integrity or availability.
Mitigation
IBM has addressed this vulnerability in IBM i Access Client Solutions versions 1.1.9.4 and later, as described in the security bulletin [1]. Users should upgrade to the fixed version. No workarounds are documented. The CVE is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog as of the publication date.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
21.1.2 through 1.1.4, 1.1.4.3 through 1.1.9.3+ 1 more
- (no CPE)range: 1.1.2 through 1.1.4, 1.1.4.3 through 1.1.9.3
- (no CPE)range: 1.1.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.ibm.com/support/pages/node/7091942mitrevendor-advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/268270mitrevdb-entry
News mentions
0No linked articles in our index yet.