Impact
The vulnerability allows a remote authenticated attacker to execute arbitrary Control Language commands on IBM i because the system fails to properly validate input. This can result in full system compromise, data exfiltration, or alteration of critical system configurations. The weakness is an OS command injection flaw (CWE‑78).
Affected Systems
IBM i versions 7.3, 7.4, 7.5, and 7.6 are affected. The issue is present in all sub‑sub‑release 0 variants of these major releases. Users of any of these releases should verify whether they are running the vendor‑supplied PTFs listed by IBM.
Risk and Exploitability
With a CVSS score of 8.3 the vulnerability is considered high severity. The EPSS score is not available, but the lack of a KEV listing does not preclude exploitation. The likely attack vector is a remote connection over a network where the attacker has valid credentials; once authenticated, the attacker can supply malicious input to trigger the command injection.
OpenCVE Enrichment