Impact
A local authenticated attacker can trigger a denial of service by exploiting improper neutralization of special elements in an SQL command. The flaw does not grant privilege escalation or data exfiltration; its effect is limited to interrupting or crashing the affected system or application. Because the vulnerability resides in database query handling, the impact remains confined to the local system executing the flawed SQL statements.
Affected Systems
The affected product is IBM i, specifically releases 7.6, 7.5, 7.4, and 7.3. IBM portal provides component level fixes: for 7.6, PTF SJ10867; for 7.5, PTF SJ10868; for 7.4, PTF SJ10869; and for 7.3, PTF SJ10870. Users of unsupported or older versions should upgrade to a supported and fixed release.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity, but the exploit requires local authenticated access, limiting the threat surface to users who can log on to the IBM i system. EPSS scores are not available. The vulnerability is not listed in the CISA KEV catalog. Due to the lack of a remote exploit path, the risk is moderate in environments with strict local access controls, yet the impact on availability can be significant if the flaw is triggered during critical operations.
OpenCVE Enrichment