Executive brief
IBM i Access Client Solutions is a remote access tool used to manage IBM i systems. An authenticated user can inject arbitrary operating system commands through a CL command input field, allowing execution of commands with normal user privileges on the system. This could allow an attacker with valid credentials to compromise system integrity or access sensitive data.
Technical details
IBM i Access Client Solutions is vulnerable to OS command injection (CWE-78) in the STRPCCMD CL command handler due to improper validation and sanitization of user-supplied input. An authenticated user can inject shell metacharacters and arbitrary commands through the vulnerable parameter. The attack requires network access and valid authentication credentials; no user interaction is needed. A successful attack allows the attacker to execute arbitrary OS commands with the privileges of the authenticated user, potentially leading to data theft, system modification, or further privilege escalation. The vulnerability can be remediated by upgrading to version 1.1.9.16 or later.
Affected products
- IBM i Access Client Solutions 1.1.2.0 through 1.1.9.15
Timeline
- 2026-09-14: disclosed
- 2026-09-14: patched: Fixed in version 1.1.9.16 and later