Impact
This vulnerability is a stored cross‑site scripting flaw in the IBM i Web UI. An attacker who is authenticated to the system can insert arbitrary JavaScript that is subsequently executed by other users browsing the UI. The injected script can manipulate the UI and potentially read session data, leading to disclosure of credentials within a trusted session. The weakness corresponds to CWE‑79.
Affected Systems
IBM i versions 7.6, 7.5, 7.4 and 7.3 are affected. To remediate, IBM recommends installing the PTFs Sj10887, Sj10888, Sj10890 and Sj10891 respectively, which can be downloaded from IBM Fix Central.
Risk and Exploitability
The CVSS score is 6.4, indicating a moderate severity. Exploit probability is not publicly available, and the vulnerability has not been listed in the CISA KEV catalog. The likely attack vector requires an authenticated session and local or remote access to the Web UI, but unauthenticated users cannot inject malicious code. As a result, the risk is moderate and the vulnerability is best mitigated by applying the vendor patches.
OpenCVE Enrichment