Impact
The vulnerability in IBM i versions 7.3 through 7.6 permits a remote authenticated attacker to execute arbitrary operating‑system commands. The flaw arises from failure to properly neutralize special elements that are incorporated into OS command strings. Successful exploitation would give the attacker full control over the target system, enabling data theft, tampering, or further lateral movement.
Affected Systems
IBM i Release 7.6, 7.5, 7.4, and 7.3 are affected. The vulnerability applies to installations running the specified releases, as identified by the vendor/product name IBM i and the listed version ranges. Users of IBM i 7.3, 7.4, 7.5, or 7.6 must verify whether the latest patch set forms are in place. All versions currently supported by IBM are included.
Risk and Exploitability
CVSS score of 8.8 classifies this flaw as high severity. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is remote over authenticated connections; the attacker must possess valid credentials or administrative access to the system. The ability to run arbitrary commands poses a severe threat to confidentiality, integrity, and availability of the affected IBM i environment.
OpenCVE Enrichment