Impact
IBM i Access Client Solutions versions 1.1.2.0 through 1.1.9.15 allow an authenticated user to execute arbitrary commands on the system due to improper validation of user-supplied command. The flaw is a classic command injection vulnerability (CWE‑78) that permits a user to run any command that their account is permitted to execute on the target machine.
Affected Systems
The vulnerability affects the IBM i Access Family product line. Any installation of IBM i Access Client Solutions with a version number between 1.1.2.0 and 1.1.9.15 inclusive is impacted. Upgrading to version 1.1.9.16 or later resolves the issue.
Risk and Exploitability
The CVSS score of 6.3 categorizes the vulnerability as medium severity. The exploit probability (EPSS) is currently low at < 1%, and the vulnerability is not listed in the CISA KEV catalog. An attacker who can authenticate to the system can supply malicious input to the STRPCCMD command, causing the system to execute arbitrary commands with the privileges of the authenticated user. This can lead to privilege abuse or facilitate further lateral movement or persistence, depending on the user account’s permissions and other system configurations.
OpenCVE Enrichment