Impact
IBM i Access Client Solutions versions 1.1.2.0 through 1.1.9.13 allow downloading of unverified product code when configured to update from an IBM i system. This flaw permits an attacker to supply malicious code that the client will download and execute, effectively enabling remote code execution on the user’s workstation. The vulnerability is identified as CWE‑494, underscoring the risk of executing untrusted code.
Affected Systems
The affected products are IBM i Access Client Solutions, specifically the 1.1.2.0 to 1.1.9.13 releases. Any installation that uses the automatic update feature and pulls updates from an IBM i environment is at risk unless updated to 1.1.9.14 or later. The CVE covers both the base client and related updater components, and any version between the stated range is susceptible.
Risk and Exploitability
This issue carries a high CVSS score of 8.3, indicating significant severity, though EPSS data is not available and the vulnerability is not yet listed in CISA’s KEV catalog. The attack vector appears to be remote through the update mechanism; a malicious actor would need access to the IBM i system providing the update or influence the update source to serve forged code. Successful exploitation would allow arbitrary code execution on the workstation, compromising confidentiality, integrity, and availability of the client environment. The risk is heightened if automatic updates are enabled and the update source is not authenticated.
OpenCVE Enrichment