Impact
A path traversal flaw in IBM i Navigator for i allows an authenticated remote user to request files outside the intended directories, enabling the attacker to read confidential data and overwrite or delete files. The vulnerability is mapped to CWE-22 and is scored with a CVSS of 4.3, indicating moderate severity. The attack does not provide privilege escalation, but it does compromise confidentiality and integrity of system files and any data stored there.
Affected Systems
IBM i operating system versions 7.6, 7.5, 7.4, and 7.3 running Navigator for i are affected. PTFs that remediate the issue are SJ10887 for 7.6, SJ10888 for 7.5, SJ10890 for 7.4, and SJ10891 for 7.3. Users on unsupported versions are advised to upgrade to a supported release that includes the fix.
Risk and Exploitability
The CVSS score of 4.3 signals a moderate risk; the EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw requires remote authentication, an attacker must first gain valid credentials or access to an authenticated session; once authenticated, the path traversal can be leveraged. The likelihood of exploitation is therefore limited to environments where credentials are compromised or where the attacker can deploy an authenticated session.
OpenCVE Enrichment