Impact
This vulnerability stems from improper session management within IBM i’s Digital Certificate Manager, allowing a remote authenticated user to perform actions beyond their intended privileges and to retrieve sensitive information. The flaw is classified as CWE‑294, reflecting a weakness where session data can be misinterpreted or altered to bypass security controls. As a result, an attacker who has already authenticated can expand their access rights, potentially accessing or manipulating protected resources that they should not be able to touch.
Affected Systems
IBM i versions 7.6, 7.5, 7.4, and 7.3 are affected. The specific Patch Tracking Files that address this session‑management flaw are PTF SJ10907 for 7.6, PTF SJ10906 for 7.5, PTF SJ10905 for 7.4, and PTF SJ10904 for 7.3, each published as part of Option 34 for the respective release.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity, and the vulnerability is exploitable remotely by an authenticated attacker who may obtain data or elevate privileges. EPSS data is not available, so the current measurable exploitation probability is unknown, yet the lack of a KEV listing suggests no widespread, actively used exploit is documented. Organizations running the affected IBM i releases should treat this as a high‑risk exposure and prioritize mitigating actions.
OpenCVE Enrichment