Impact
IBM i Navigator for i contains an XML injection flaw that permits a remote authenticated attacker to read sensitive data and modify system state. The vulnerability, identified as CWE-346, arises because the application trusts user‑supplied XML without sufficient validation, enabling unintended interpretation of XML content.
Affected Systems
Vulnerable platforms include IBM i 7.6, 7.5, 7.4, and 7.3. These versions can be affected if the Navigator for i component is present, regardless of minor sub‑release variations.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity. EPSS data is not available, but the presence of a remote authenticated attack vector suggests that malicious users with legitimate credentials can exploit the flaw. The vulnerability is not listed in CISA KEV, indicating no current known active exploitation, yet the high severity warrants immediate mitigation.
OpenCVE Enrichment