Impact
IBM i Access Client Solutions (i Access Family) versions 1.1.2.0 through flaw in the RunProgram macro of the emulator. Improper validation of user‑supplied input allows an authenticated user to supply a macro that triggers the execution of arbitrary shell commands with the same privilege level as the user. The vulnerability is therefore a command‑execution weakness (CWE‑78) that can be leveraged to run malicious instructions within the context of a valid account.
Affected Systems
Affected systems are IBM i Access Family client solutions on IBM i platforms. The CVE impacts all installations from version 1.1.2.0 up to and including 1.1.9.15; no other releases are known to be affected.
Risk and Exploitability
The CVSS base score is 6.3, indicating a moderate likelihood of exploitation. The EPSS score of less than 1% suggests a very low probability of being targeted in the wild. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an attacker to have valid credentials that permit macro execution; the attack vector is therefore local or remote with authentication, and the malicious macro can run arbitrary commands under the user’s rights.
OpenCVE Enrichment