Impact
An improper neutralization of special elements in IBM i's debug server exposes a CWE-78 vulnerability, allowing a local authenticated attacker to inject arbitrary parameters into a CL command. The injected parameters can cause the command to execute unintended operations, potentially enabling the attacker to gain elevated privileges or compromise system integrity. The flaw stems from OS command injection where untrusted input is passed directly to the command processor.
Affected Systems
Versions of IBM i from 7.3 through 7.6 that run the debug server are affected. The vulnerability is present in IBM i 7.3, 7.4, 7.5, and 7.6, and is documented for all four releases.
Risk and Exploitability
The CVSS score of 4.4 indicates a medium severity, and the EPSS score is not available, suggesting a low to moderate probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, which implies no confirmed widespread exploitation. However, the attack requires a local, authenticated user with access to the debug server, so restrict or disable the server if it is not needed to reduce the attack surface.
OpenCVE Enrichment