Impact
The vulnerability present in IBM i 7.6, 7.5, 7.4, and 7.3 permits a local attacker to bypass security controls by supplying a crafted LANG environment variable. This improper validation can lead to uncontrolled privilege escalation, allowing the attacker to run commands or services with elevated system privileges. The weakness is identified as CWE-73.
Affected Systems
Systems affected include IBM i releases 7.6, 7.5, 7.4, and 7.3 across all options that support the PASE environment. PTFs such as SJ10846 for 7.6, SJ10847 for 7.5, SJ10852 for 7.4, and SJ10854 for 7.3 provide the fix. Versions beyond 7.6 are not listed, so they are not known to be affected.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity. The EPSS score is not available, so the likelihood of exploitation is uncertain, though its inclusion in the IBM advisory signals that the vendor considers it a serious issue. The vulnerability can be exploited by users who can set or influence the LANG variable on the system, typically via local interactive or scripted sessions. No public exploits are documented, and the vulnerability is not listed in the CISA KEV catalog, but IBM strongly recommends addressing it immediately.
OpenCVE Enrichment