Impact
The vulnerability allows an attacker to exploit the Zip Slip path traversal flaw that occurs when importing a configuration file into IBM i Access Client Solutions. By crafting a malicious archive, the attacker can cause the application to write files outside the intended directory, potentially overwriting critical system files or dropped payloads. This arbitrary file write can lead to local or remote code execution depending on the privileges of the user performing the import.
Affected Systems
Affected are IBM i Access Client Solutions versions 1.1.2.0 through 1.1.9.13. The vulnerability applies to all instances of the product listed by IBM as i Access Client Solutions.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity vulnerability. Although EPSS is not available, the lack of availability and the nature of the flaw suggest a realistic exploitation possibility, especially in environments where configuration import is enabled for untrusted users. The vulnerability is not listed in the CISA KEV catalog, but its high CVSS and potential for remote code execution make it a priority for remediation.
OpenCVE Enrichment