Impact
An SQL injection flaw exists in IBM i version 7.3 through 7.6 that lets a remote attacker craft malicious SQL commands. The attacker could read, insert, modify, or delete records in the backend database, effectively compromising data confidentiality, integrity, and availability. The weakness is a classic injection flaw classified as CWE-89.
Affected Systems
IBM i operating systems releases 7.3, 7.4, 7.5, and 7.6 are affected. Users of any of these versions should apply the relevant Product Fixes (PTFs) – for example SJ10867 for 7.6, SJ10868 for 7.5, SJ10869 for 7.4, and SJ10870 for 7.3 – or upgrade to a newer, supported release that includes the fix.
Risk and Exploitability
The CVSS score of 7.6 indicates high severity, while the EPSS value is not available, so the exact likelihood of exploitation is unknown. The vulnerability is not listed in CISA’s KEV catalog, but it is a remote exploit that can be triggered without local access. Given that the flaw allows critical database operations, the potential impact remains significant.
OpenCVE Enrichment