Impact
The vulnerability arises from improper neutralization of special elements used in an operating system command within the IBM i Debug Server. This flaw can allow a local attacker to execute arbitrary commands on the affected system, potentially compromising system integrity and confidentiality. The weakness is classified under CWE-78, indicating a classic command injection scenario where input is not properly sanitized before inclusion in OS commands.
Affected Systems
The flaw affects IBM i versions 7.6, 7.5, 7.4, and 7.3. IBM’s official advisory lists specific PTFs for each version: SJ11305 for 7.6, SJ11306 for 7.5, SJ11307 for 7.4, and SJ11308 for 7.3. Systems running any of these versions are susceptible if the Debug Server component is installed and accessible to local users.
Risk and Exploitability
Because the vulnerability requires local access, an attacker must be able to log on to the IBM i system or gain local credentials. The CVSS score of 5.3 reflects moderate severity, with the impact limited to local users. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting low current exploitation activity. However, the inability to neutralize command elements makes the risk significant if local privileges exist. An attacker who exploits this flaw can run arbitrary commands, potentially leading to full system compromise.
OpenCVE Enrichment