Impact
The vulnerability allows a remote authenticated user to execute arbitrary commands on IBM i systems because shell metacharacters are not properly neutralized, enabling complete compromise of the affected system through command injection (CWE‑78).
Affected Systems
IBM i (IBM) versions 7.6, 7.5, 7.4, and 7.3 are affected. The advisory lists specific PTFs: SJ10968 for 7.6, SJ10966 for 7.4, and SJ10964 for 7.3. Users of unsupported releases should upgrade to a supported, fixed version of IBM i.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity vulnerability. No EPSS score is available and the flaw is not listed in the CISA KEV catalog. Exploitation requires remote authenticated access; once credentials are present, an attacker can run arbitrary shell commands. While authentication limits the threat to users or processes with valid credentials, the impact on confidentiality, integrity, and availability is severe.
OpenCVE Enrichment