Impact
In IBM i 7.6 through 7.3, a flaw in the Digital Certificate Manager allows a remote authenticated attacker to bypass the framework's anti‑CSRF token checks. This flaw, identified as CWE‑352, lets an attacker perform actions that the authenticated application would otherwise reject, potentially altering certificate configuration or revocation information. The vulnerability does not provide code execution but can be used to manipulate the system in ways that the user has not authorized.
Affected Systems
The affected product line is IBM i versions 7.6, 7.5, 7.4, and 7.3, all of which still expose the Digital Certificate Manager without the latest patches. IBM PTFs that address the issue are listed as SJ10907 for 7.6, SJ10906 for 7.5, SJ10905 for 7.4, and SJ10904 for 7.3. The vulnerability is present across all standard PTF levels (Option 34) and applies to product releases that contain this component.
Risk and Exploitability
The vulnerability has a CVSS score of 8.1, categorizing it as high severity. Because a valid authenticated session is required, the likelihood of exploitation depends on the attacker’s ability to obtain legitimate credentials. The EPSS score is not available, but the vulnerability is not listed in CISA’s KEV catalog, indicating that no public exploits have been confirmed. If the environment has exposed credentials or weak password policies, the risk rises markedly. Users should treat the flaw as a significant threat that requires immediate mitigation.
OpenCVE Enrichment