Executive brief
IBM i is an enterprise operating system used to run mission-critical business applications. A local attacker with basic access privileges can execute arbitrary commands on the system by exploiting improper input validation in the Debug Server component, potentially compromising data confidentiality, system integrity, and availability across affected environments.
Technical details
This vulnerability is a classic OS command injection (CWE-78) in IBM i's Debug Server component affecting versions 7.3 through 7.6. The vulnerability arises from improper neutralization of special elements in OS commands, allowing a local attacker with limited privileges (PR:L) to execute arbitrary commands without user interaction. The attack vector is local only (AV:L), and no complex conditions are required (AC:L). A successful exploit grants the attacker command execution with the privileges of the affected process, enabling full system compromise. IBM has released PTF patches (SJ11305–SJ11308) for all affected versions.
Affected products
- IBM i 7.3, 7.4, 7.5, 7.6
Timeline
- 2026-09-04: disclosed
- 2026-09-04: patched: PTF patches released: 7.6 (SJ11305), 7.5 (SJ11306), 7.4 (SJ11307), 7.3 (SJ11308)