Impact
An untrusted search path vulnerability (CWE‑426) in WebSphere Application Server Liberty running on IBM i allows a remote authenticated attacker to execute arbitrary code. The flaw permits execution of code that an attacker can supply by manipulating the search path used by the server. This capability can lead to full compromise of the IBM i system where the attacker controls code execution on the host.
Affected Systems
IBM i releases 7.6, 7.5, 7.4, and 7.3 are affected. The error is present in the WebSphere Application Server Liberty component on these releases. IBM provides Product Temporary Fixes (PTFs) for each release: 7.6 requires PTFs SJ10874 and SJ11023, 7.5 requires SJ10875 and SJ11024, 7.4 requires SJ10876 and SJ11025, and 7.3 requires SJ10877 and SJ11026. Users of unsupported or older IBM i versions should consider upgrading to a supported release that includes the fix.
Risk and Exploitability
The CVSS score of 8.8 categorizes this flaw as high severity. The EPSS score is not available, and it is not listed in the CISA KEV catalog, indicating there is no publicly known exploitation activity at the time of this analysis. The likely attack vector involves a remote authenticated attacker that can send inputs to WebSphere Application Server Liberty. IBM explicitly recommends that users address the vulnerability immediately, implying a significant risk if patches are not applied.
OpenCVE Enrichment