Impact
The flaw is improper neutralization of special elements in an OS command within the IBM i debug server that can be exploited by a remote authenticated attacker to cause a denial of service. Exploitation of this OS command injection leads to a service interruption on the affected system.
Affected Systems
IBM i versions 7.3 through 7.6 are affected. 7.3, 7.4, 7.5, and 7.6 each contain the vulnerable debug server component. IBM publishes specific patch facility tags to remediate the issue: PTF SJ10916 for 7.3, PTF SJ10915 for 7.4, PTF SJ10903 for 7.5, and PTF SJ10899 for 7.6. Unsupported or older releases should be upgraded to a supported, patched release.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, so the exploitation probability is uncertain but the authentication barrier limits attacker access to users with valid credentials. The attack would need a remotely authenticated connection to the debug server, after which the attacker can trigger a denial of service. The impact is a loss of availability, but confidentiality and integrity are not directly affected.
OpenCVE Enrichment