Impact
The vulnerability in IBM i arises from an improper neutralization of special elements in an SQL parameter. A remote authenticated attacker can exploit this flaw to bypass security restrictions, potentially gaining unauthorized access to privileged operations or sensitive data.
Affected Systems
Affected IBM i releases include 7.3, 7.4, 7.5, and 7.6. IBM provides Platform Translations (PTFs) SJ10870 for 7.3, SJ10869 for 7.4, SJ10868 for 7.5, and SJ10867 for 7.6 to address the issue.
Risk and Exploitability
With a CVSS score of 6.3, the vulnerability presents moderate risk. Although EPSS data is not available, the lack of registration in the CISA KEV catalog suggests no widespread, publicly available exploits are known. Nevertheless, because it requires remote authenticated access, attackers with legitimate credentials or those who can compromise user accounts could bypass security controls. Promptly applying the vendor’s PTFs mitigates this risk.
OpenCVE Enrichment