Impact
An authenticated attacker who can place a script on an IBM i system can trigger the activation engine component to execute that script with superuser privileges. This grants full control over the affected host, allowing the attacker to modify system files, compromise services, or establish persistence. The flaw is a classic privilege escalation via remote code execution, classified as CWE‑250.
Affected Systems
IBM i versions 7.3, 7.4, 7.5, and 7.6 are affected. The fix is supplied through IBM’s Problem Tracking Facility downloads: SJ11009 for 7.6, SJ10978 for 7.5, SJ10977 for 7.4, and SJ10976 for 7.3. Administrators running unsupported or older releases should plan an upgrade to the latest supported IBM i release.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.8, indicating high severity and high impact. Though no EPSS score is available and it is not listed in CISA KEV, the high score warrants immediate attention. The exploit requires authenticated access, so it is most likely to be leveraged by attackers who have legitimate or stolen credentials. Once privilege escalation to root is achieved, any subsequent attack becomes trivially feasible. IBM strongly recommends applying the PTF immediately and there is no temporary workaround.
OpenCVE Enrichment