Impact
IBM i releases 7.3 through 7.6 contain a vulnerability in the Digital Certificate Manager that allows a remote authenticated attacker to manipulate files by exploiting a path traversal flaw. The flaw does not grant code execution but enables the attacker to modify, delete, or add files within authorized directories, potentially compromising data integrity and application behavior.
Affected Systems
The affected products are IBM i Release5770-SS1 Option 34 running versions 7.6, 7.5, 7.4, and 7.3. IBM has issued patch set features for each release: PTF SJ10907 for 7.6, SJ10906 for 7.5, SJ10905 for 7.4, and SJ10904 for 7.3. The service packs are available at the IBM support links provided in the advisories.
Risk and Exploitability
The CVSS score of 2.7 indicates a low severity vulnerability. The EPSS score is presently unavailable, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no widespread exploitation has been observed. Exploitation requires remote authenticated access to the affected IBM i system, after which the attacker can perform file manipulation via path traversal. The limited scope and low CVSS score imply a moderate but not critical risk if the system is actively used in a production environment.
OpenCVE Enrichment