Impact
This vulnerability allows a local attacker to gain elevated privileges on IBM i systems by executing arbitrary OS commands that contain unescaped special elements, resulting in OS Command Injection (CWE-78). The flaw originates from improper neutralization of command‑line parameters, enabling the attacker to run arbitrary code with system privileges.
Affected Systems
IBM i Release 7.5 and 7.6, including option 33, are affected. Users of these versions should apply the provided fix packages: PTF SJ10931 for 7.6 and PTF SJ11010 for 7.5. IBM also recommends upgrading to a supported and fixed release if running an unsupported version.
Risk and Exploitability
The CVSS score of 8.8 indicates a high risk of exploitation, while EPSS is not available and the vulnerability is not listed in CISA KEV. The issue requires local access; the likely attack vector is a local attacker who can run commands on the affected system. Once exploited, the attacker can elevate privileges to administrative levels, enabling full control over the operating system.
OpenCVE Enrichment