Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to perform file manipulation due to path traversal.
Published: 2026-08-13
Score: 2.7 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM i releases 7.3 through 7.6 contain a vulnerability in the Digital Certificate Manager that allows a remote authenticated attacker to manipulate files by exploiting a path traversal flaw. The flaw does not grant code execution but enables the attacker to modify, delete, or add files within authorized directories, potentially compromising data integrity and application behavior.

Affected Systems

The affected products are IBM i Release5770-SS1 Option 34 running versions 7.6, 7.5, 7.4, and 7.3. IBM has issued patch set features for each release: PTF SJ10907 for 7.6, SJ10906 for 7.5, SJ10905 for 7.4, and SJ10904 for 7.3. The service packs are available at the IBM support links provided in the advisories.

Risk and Exploitability

The CVSS score of 2.7 indicates a low severity vulnerability. The EPSS score is presently unavailable, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no widespread exploitation has been observed. Exploitation requires remote authenticated access to the affected IBM i system, after which the attacker can perform file manipulation via path traversal. The limited scope and low CVSS score imply a moderate but not critical risk if the system is actively used in a production environment.

Generated by OpenCVE AI on August 13, 2026 at 21:51 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release5770-SS1 Option 34 PTF Number(s)PTF Download Link(s)7.6SJ10907 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10907 7.5SJ10906 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10906 7.4SJ10905 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10905 7.3SJ10904 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10904 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Install the appropriate PTF for your IBM i release (SJ10907 for 7.6, SJ10906 for 7.5, SJ10905 for 7.4, or SJ10904 for 7.3).
  • Upgrade any unsupported IBM i releases to a supported value that contains the fix, following IBM’s recommendation to exit unsupported products.
  • If immediate patching cannot be applied, restrict or isolate remote access to the Digital Certificate Manager to prevent authenticated attackers from leveraging the path traversal flaw.

Generated by OpenCVE AI on August 13, 2026 at 21:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to perform file manipulation due to path traversal.
Title IBM i is Affected By Multiple Vulnerabilities in Digital Certificate Manager
First Time appeared Ibm
Ibm i
Weaknesses CWE-22
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-13T20:22:52.009Z

Reserved: 2026-07-24T14:09:14.516Z

Link: CVE-2026-17071

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-13T21:17:41.130

Modified: 2026-08-13T21:17:41.130

Link: CVE-2026-17071

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T23:00:06Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')