Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a path traversal vulnerability.
Published: 2026-08-13
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM i 7.6, 7.5, 7.4, and 7.3 include a path traversal vulnerability in the Digital Certificate Manager that can be exploited by a remote authenticated attacker to obtain sensitive data. The weakness, classified as CWE‑22, compromises confidentiality by allowing the attacker to read files outside the intended directory structure.

Affected Systems

Affected systems are IBM i versions 7.6, 7.5, 7.4, and 7.3. Installers for these releases are available: PTF SJ10907 for 7.6, SJ10906 for 7.5, SJ10905 for 7.4 and SJ10904 for 7.3. Users running unsupported versions of IBM i products should upgrade to a supported, fixed release.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity. EPSS is not available, and the vulnerability is not listed in CISA's KEV catalog. Exfiltration requires valid credentials, so the attacker must authenticate before sending a request that triggers the traversal. No additional prerequisites or conditions are disclosed beyond remote authenticated access.

Generated by OpenCVE AI on August 13, 2026 at 22:09 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release5770-SS1 Option 34 PTF Number(s)PTF Download Link(s)7.6SJ10907 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10907 7.5SJ10906 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10906 7.4SJ10905 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10905 7.3SJ10904 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10904 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Install the IBM i PTFs (SJ10907 for 7.6, SJ10906 for 7.5, SJ10905 for 7.4, SJ10904 for 7.3) to apply the fix.
  • Upgrade any unsupported IBM i versions to a supported release that includes the patch.
  • Limit access and privileges for the Digital Certificate Manager service to prevent unauthorized traversal attempts.

Generated by OpenCVE AI on August 13, 2026 at 22:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a path traversal vulnerability.
Title IBM i is Affected By Multiple Vulnerabilities in Digital Certificate Manager
First Time appeared Ibm
Ibm i
Weaknesses CWE-22
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-13T20:26:19.464Z

Reserved: 2026-07-24T14:43:33.274Z

Link: CVE-2026-17088

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-13T21:17:41.900

Modified: 2026-08-13T21:17:41.900

Link: CVE-2026-17088

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T22:15:03Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')