Vulnerability Reference

Default and weak passwords on powerful profiles (QSECOFR and equivalents)

Critical Last verified

What Happened

Industry surveys of live IBM i shops, including Fortra's annual State of IBM i Security Study, have repeatedly found a meaningful share of systems with default or weak passwords still active on QSECOFR or equivalent *ALLOBJ/*SECADM-authority profiles.

Why It Matters

A profile with *ALLOBJ and *SECADM special authorities can read, change, or delete anything on the system and administer other users' authority. A weak or default password on such a profile is close to a complete compromise if reached.

Recommended Actions

  • Force a password change on QSECOFR and any other profile carrying *ALLOBJ or *SECADM special authority
  • Set QPWDEXPITV and related system values to enforce regular password rotation on powerful profiles
  • Move day-to-day administration to named, individually-owned profiles rather than shared use of QSECOFR
  • Add MFA in front of any sign-on path that can reach a powerful profile

Sources

This is a recurring vulnerability class, not a single-incident CVE. It shows up repeatedly across live IBM i systems in industry security assessments, which is exactly why it is worth checking on yours rather than assuming it was handled.