Impact
The flaw allows an attacker to add a malicious certificate authority to the client’s truststore, enabling forged SSL/TLS certificates to be trusted by the IBM i Access Client Solutions application. This can result in man‑in‑the‑middle interception or other credential compromise scenarios. The weakness is a CWE‑798 misuse of certificate authorities.
Affected Systems
IBM i Access Client Solutions versions 1.1.2.0 through 1.1.9.13 are affected. The product must be upgraded to 1.1.9.14 or later to receive the fix. No other products or versions are listed as vulnerable.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.7, indicating a high impact when exploited. EPSS is not available and the vulnerability is not listed in CISA KEV, suggesting limited current exploitation data. The attack vector is inferred to require the ability to write to the truststore, which may be local or require elevated privileges on the workstation or server hosting ACS. If such access can be obtained, the attacker can inject a rogue CA and subsequently intercept secure communications.
OpenCVE Enrichment