Impact
IBM i Access Family 1.1.2.0 through 1.1.9.15 could allow an authenticated user to execute arbitrary commands with the privileges of a normal user due to improper validation of user‑supplied input in a session file.
Affected Systems
The affected products are IBM i Access Family, specifically versions through 1.1.9.15, inclusive. IBM recommends upgrading to version 1.1.9.16 or later to receive the fix.
Risk and Exploitability
The CVSS score of 6.3 indicates a medium severity level. The EPSS score is < 1%, indicating a low probability of exploitation in the wild; the vulnerability involves improper validation of user‑supplied input in a session file, so the attack vector is likely restricted to local or network‑based sessions, which is less widespread than remote exploits. Overall risk is moderate; however, because the flaw grants command execution, any successful exploitation could lead to further system compromise.
OpenCVE Enrichment