Impact
The vulnerability is an instance of parameter injection that allows a remote authenticated attacker to append unexpected parameters to a command executed by IBM i. This could let the attacker alter or take control of command behavior, potentially leading to unauthorized configuration changes, data modification, or privilege escalation. The weakness is identified by CWE-20, which denotes improper input validation.
Affected Systems
Affected systems include IBM i releases 7.3, 7.4, 7.5, and 7.6. The vulnerability applies across these major releases, as documented in IBM’s product fix references and the CPE entries for each version. Administrators should verify whether their servers run any of these releases and whether the corresponding PTFs have been applied.
Risk and Exploitability
The CVSS score of 4.3 indicates a medium severity risk, and the EPSS score is not available, so the current exploitation likelihood cannot be quantified. The vulnerability is not listed in CISA’s KEV catalogue, suggesting no known active exploitation at this time. The attack vector is remote with authentication required, implying that only users who can authenticate to the IBM i system can exploit this weakness. Proper patching mitigates the risk.
OpenCVE Enrichment