Impact
Authenticated users of IBM i may exploit a flaw in Navigator for i that allows privilege escalation to a root user, enabling the execution of arbitrary commands. The weakness involves an OS Command Injection vulnerability (CWE‑78). No data indicates that exploitation can occur without valid credentials, so attackers must first authenticate to the system. If successful, the attacker gains full administrative control, compromising all system confidentiality, integrity, and availability.
Affected Systems
IBM i releases 7.6, 7.5, 7.4, and 7.3 are affected. IBM issued PTFs SJ10887, SJ10888, SJ10890, and SJ10891 for the 7.6, 7.5, 7.4, and 7.3 releases respectively, under the Release 5770‑SS1 Option 3 configuration. The vulnerability is relevant for any system running an unsupported IBM i version; these versions should be replaced with a supported and patched release.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity. The EPSS score is not available, so the current estimate of exploitation probability is unknown, but the lack of KEV listing suggests no widespread exploitation has been observed yet. Exploitation requires authentication to Navigator for i, after which elevated privileges can be obtained. The combination of high impact and the need for user credentials makes the risk significant for environments with broad user access or weak account controls.
OpenCVE Enrichment