Impact
The vulnerability stems from improper neutralization of special elements that are incorporated into operating system commands. A local attacker who can run the IBM i Access Client Solutions application can cause the system to execute arbitrary commands with the privileges of the user running the application, potentially leading to full control of the affected IBM i server.
Affected Systems
IBM i Access Client Solutions versions 1.1.2.0 through 1.1.9.13 are vulnerable. The affected installations run on IBM i systems and include all releases in that range.
Risk and Exploitability
The CVSS score of 7.8 signifies high severity; however, the flaw is local, meaning an attacker must have access to the target system or be able to log into the client application. EPSS data is not available, so the exploit probability cannot be quantified; the vulnerability is not listed in the CISA KEV catalog. The absence of remote exploitation barriers raises the risk level for environments where local users could exploit the client.
OpenCVE Enrichment