Impact
IBM i 7.6, 7.5, 7.4, and 7.3 include a path traversal vulnerability in the Digital Certificate Manager that can be exploited by a remote authenticated attacker to obtain sensitive data. The weakness, classified as CWE‑22, compromises confidentiality by allowing the attacker to read files outside the intended directory structure.
Affected Systems
Affected systems are IBM i versions 7.6, 7.5, 7.4, and 7.3. Installers for these releases are available: PTF SJ10907 for 7.6, SJ10906 for 7.5, SJ10905 for 7.4 and SJ10904 for 7.3. Users running unsupported versions of IBM i products should upgrade to a supported, fixed release.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. EPSS is not available, and the vulnerability is not listed in CISA's KEV catalog. Exfiltration requires valid credentials, so the attacker must authenticate before sending a request that triggers the traversal. No additional prerequisites or conditions are disclosed beyond remote authenticated access.
OpenCVE Enrichment