Impact
Improper validation of session tokens in IBM i 7.3, 7.4, 7.5, and 7.6 allows a remote authenticated attacker to bypass security restrictions. This flaw is a CWE‑294 vulnerability.
Affected Systems
The affected product is IBM i, versions 7.3, 7.4, 7.5, and 7.6 SR1 Option 3. Patches are available per release: 7.6SJ10887 for 7.6, 7.5SJ10888 for 7.5, 7.4SJ10890 for 7.4, and 7.3SJ10891 for 7.3. These fixes address the token validation logic in Navigator for i.
Risk and Exploitability
The CVSS score is 6.8 indicating medium severity. No EPSS score is available and it is not listed in KEV, but the vulnerability requires remote authenticated access, implying an attacker must possess valid credentials. IBM recommends addressing the flaw immediately, and the correction is delivered via the provided PTFs. Until patched, systems remain vulnerable.
OpenCVE Enrichment