Impact
The vulnerability arises from improper validation of authentication tokens in IBM i's Digital Certificate Manager. A remote attacker who can control the token handling process may obtain confidential data and trigger privileged operations. The flaw maps to CWE‑287, which describes incorrect verification of credentials, allowing attackers to bypass intended restrictions because the system relies on token integrity to grant access.
Affected Systems
IBM i releases 7.3, 7.4, 7.5, and 7.6 are affected. The affected product is IBM i in all its supported releases within these major version numbers. The PTFs that address the flaw are SJ10904 for 7.3, SJ10905 for 7.4, SJ10906 for 7.5, and SJ10907 for 7.6.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.5, indicating moderate severity. EPSS data is not available and the flaw is not listed in CISA’s KEV catalog. The attack vector is remote and exploits the ability to supply crafted authentication tokens to the Digital Certificate Manager. While no public exploit has been disclosed, the potential for unauthorized data access or administrative operation execution warrants prompt remediation.
OpenCVE Enrichment