Impact
A remote authenticated attacker can inject arbitrary content into Navigator log files on IBM i 7.6, 7.5, 7.4, or 7.3 due to improper output neutralization for logs. This weakness is classified as CWE‑117 and can corrupt log data or facilitate the concealment of malicious activity. The vulnerability does not directly provide code execution or privilege escalation, but compromised logs may aid attackers in evading detection or causing confusion in troubleshooting.
Affected Systems
The affected systems are IBM i product releases 7.6, 7.5, 7.4, and 7.3, each of which includes a Navigator component. IBM provides specific patch install fixes for these releases: 7.6SJ10887 for 7.6, 7.5SJ10888 for 7.5, 7.4SJ10890 for 7.4, and 7.3SJ10891 for 7.3. Users of unsupported or older releases should consider upgrading to a supported and fixed version as recommended by IBM.
Risk and Exploitability
The CVSS score is 4.3, indicating a moderate severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack requires the attacker to be authenticated to the Navigator service, which limits the scope compared to an unauthenticated vector. Once authenticated, the attacker can tamper with log contents, potentially leading to data corruption or misleading audit trails, but the likelihood of exploitation remains moderate due to the need for valid credentials and the limited impact surface.
OpenCVE Enrichment