Impact
A remote authenticated attacker can read files outside a restricted directory on affected IBM i systems, which may contain confidential information. The vulnerability arises from improper limitation of a pathname, allowing the attacker to exploit path traversal weaknesses to gain unauthorized access to system data.
Affected Systems
IBM i 7.6, 7.5, 7.4, and 7.3 – versions that form part of the Navigator for i platform – are vulnerable.
Risk and Exploitability
The CVSS score of 6.5 classifies the flaw as medium severity; no EPSS score is available, and it is not listed in the CISA KEV catalog. The attack requires remote authentication but does not need local privileges, so an adversary with valid user credentials can leverage the path traversal weakness to disclose sensitive files.
OpenCVE Enrichment