Impact
IBM i versions 7.3 through 7.6 are vulnerable to a path traversal flaw in the Digital Certificate Manager that permits a remote authenticated attacker to delete arbitrary files. The weakness, identified as CWE‑22, undermines data integrity and availability, potentially allowing the attacker to remove critical system configuration or application files.
Affected Systems
Affected products include IBM i 7.3, 7.4, 7.5, and 7.6, all of which receive the PTFs SJ10904 to SJ10907. These updates address the path traversal issue in the Digital Certificate Manager. Users operating on unsupported IBM i releases should consider upgrading to a supported, patched version.
Risk and Exploitability
The CVSS score of 3.8 indicates a moderate risk level. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog. Because the flaw requires authentication, the likely attack vector involves a remote authenticated session that can traverse filesystem paths to delete user‑specified files.
OpenCVE Enrichment