Impact
A session IP binding bypass in Navigator for i allows a remote, unauthenticated attacker to retrieve sensitive information. The vulnerability is a weakness of improper authentication (CWE‑290), enabling an attacker to bypass the IP restriction normally enforced for user sessions and read data that should be protected. The impact is a loss of confidentiality with no direct impact on integrity or availability demonstrated by the current description.
Affected Systems
The affected products are IBM i releases 7.6, 7.5, 7.4, and 7.3, specifically the Navigator for i component. In each release, several PTFs are available: for release 7.6, options 3 and 34 carry patches such as SJ11196, SJ11337, SJ11377; for release 7.5, patches include SJ11197, SJ11336, SJ11376; for release 7.4, patches include SJ11200, SJ11335, SJ11375; for release 7.3, patches include SJ11187, SJ11394, SJ11374. All supported releases require applying these fixes, and users of unsupported versions should upgrade to a supported, fixed release.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, reflecting the fact that an attacker would need network access and only benefit from data disclosure. The EPSS score is not available, but the vulnerability is not listed in the CISA KEV catalog, suggesting no known active exploitation at the time of this assessment. The attack vector is inferred to be remote over the network, as the description specifies an unauthenticated remote attacker can exploit the session IP binding bypass. Because the flaw allows direct access to sensitive information without authentication, the recommendation is to treat it as a high‑priority concern for all affected systems.
OpenCVE Enrichment