Vulnerability Reference
Default and weak passwords on powerful profiles (QSECOFR and equivalents)
What Happened
Industry surveys of live IBM i shops, including Fortra's annual State of IBM i Security Study, have repeatedly found a meaningful share of systems with default or weak passwords still active on QSECOFR or equivalent *ALLOBJ/*SECADM-authority profiles.
Why It Matters
A profile with *ALLOBJ and *SECADM special authorities can read, change, or delete anything on the system and administer other users' authority. A weak or default password on such a profile is close to a complete compromise if reached.
Recommended Actions
- Force a password change on QSECOFR and any other profile carrying *ALLOBJ or *SECADM special authority
- Set QPWDEXPITV and related system values to enforce regular password rotation on powerful profiles
- Move day-to-day administration to named, individually-owned profiles rather than shared use of QSECOFR
- Add MFA in front of any sign-on path that can reach a powerful profile
Sources
This is a recurring vulnerability class, not a single-incident CVE. It shows up repeatedly across live IBM i systems in industry security assessments, which is exactly why it is worth checking on yours rather than assuming it was handled.
Other Vulnerability Classes
- Excessive *ALLOBJ special authority assigned beyond IT administrators High severity
- Unsecured FTP, ODBC, and remote command exit points High severity
- *PUBLIC *CHANGE authority left on production libraries and files Medium severity
- IFS exposure to network-share-originated ransomware encryption High severity