Impact
The vulnerability is a command‑injection flaw in the IBM i debug server caused by insufficient neutralization of special characters in operating‑system commands. A local attacker who can reach the debug server can supply crafted input that results in arbitrary command execution with the privileges of the server process. This allows full compromise of confidentiality, integrity, and availability on the affected system, and can be leveraged to gain elevated privileges, effectively turning the operating system into an attacker‑controlled machine.
Affected Systems
The flaw affects IBM i versions 7.3, 7.4, 7.5, and 7.6. IBM has provided PTFs to address the issue: SJ11308 for 7.3, SJ11307 for 7.4, SJ11306 for 7.5, and SJ11305 for 7.6. Systems running these releases are susceptible unless they are upgraded to the supported release IBM i Release 5770‑SS1 or have the specific PTF applied.
Risk and Exploitability
The vulnerability has a CVSS score of 4.4, which indicates moderate severity, and no EPSS data is available; it is not listed in the CISA KEV catalog. Because the attack requires local access to the debug server, the exploitability is limited to users with physical or local network access, and the likelihood of widespread exploitation is low. However, once a local attacker gains a foothold, arbitrary command execution and privilege escalation can occur, making timely remediation important.
OpenCVE Enrichment