Executive brief
IBM i is a mission-critical operating system used to run enterprise business applications. A local attacker with basic privileges can exploit improper input validation in the Debug Server to execute arbitrary commands, potentially gaining control over system operations and accessing sensitive data.
Technical details
The vulnerability is an OS command injection (CWE-78) in IBM i's Debug Server, affecting versions 7.6, 7.5, 7.4, and 7.3. The flaw stems from improper neutralization of special elements in OS commands, allowing a local attacker with low privileges to inject and execute arbitrary commands. The attack vector is local, requires low privileges (PR:L), and no user interaction is needed. An attacker can achieve limited integrity and availability impact. IBM has released PTF patches (SJ11305 for 7.6, SJ11306 for 7.5, SJ11307 for 7.4, SJ11308 for 7.3) to remediate the issue.
Affected products
- IBM IBM i 7.3, 7.4, 7.5, 7.6
Timeline
- 2026-09-04: disclosed
- 2026-08-31: patched: PTF releases: SJ11305 (7.6), SJ11306 (7.5), SJ11307 (7.4), SJ11308 (7.3)