Impact
The vulnerability is an OS command injection flaw caused by failure to neutralize special elements in an OS command string. A remote authenticated attacker can exploit this flaw to run arbitrary commands with elevated system privileges, potentially compromising the confidentiality, integrity, and availability of the IBM i platform.
Affected Systems
IBM i versions 7.5 and 7.6 are affected. IBM recommends applying PTF SJ11010 for 7.5 and PTF SJ10931 for 7.6, or upgrading to a newer supported release if the current installation is unsupported.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The impact is limited to systems for which the attacker has authentication credentials; the attack vector is remote, requiring valid credentials to execute the injected commands.
OpenCVE Enrichment