Impact
The vulnerability stems from improper neutralization of special elements within SQL commands, enabling a remote authenticated attacker to inject malicious SQL and modify data stored in specific tables. This primarily compromises data integrity, as the attacker can alter, delete, or insert records, potentially leading to corrupted database state or loss of trust in system data. The flaw does not explicitly disclose confidentiality or availability impacts, but widespread data tampering can indirectly lead to application errors or downtime.
Affected Systems
Affected systems are IBM i releases 7.3, 7.4, 7.5, and 7.6. IBM recommends applying the PTFs: SJ10870 for 7.3, SJ10869 for 7.4, SJ10868 for 7.5, and SJ10867 for 7.6.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed exploitation yet. Nevertheless, the attack requires remote authenticated access, implying that compromised or privileged user accounts could exploit the flaw. The risk is primarily driven by the potential for data integrity compromise rather than an immediate code execution or denial of service threat.
OpenCVE Enrichment