Impact
The vulnerability arises from improper validation of user-supplied path input in IBM i Navigator for i, allowing a remote authenticated attacker to access files and directories that should not be exposed. This flaw is a classic example of a path traversal issue, classified as CWE-22. The consequence is the disclosure of potentially confidential data, which could compromise the confidentiality and integrity of the affected system.
Affected Systems
IBM i releases 7.3, 7.4, 7.5, and 7.6 running Option 3 are vulnerable. The impact applies to all supported versions within those releases, and users of unsupported versions should consider upgrading to a fixed product version. Patching with the following Fix Related Files (FRFs) is recommended: SJ10887 for 7.6, SJ10888 for 7.5, SJ10890 for 7.4, and SJ10891 for 7.3.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity for this flaw. EPSS data is not available, making it unclear how frequently attackers target this issue, but the lack of a KEV listing suggests no large-scale exploitation has been observed. The flaw requires authentication, so only users with valid credentials can exploit it; attackers typically need to log in via the Navigator for i interface or a related service to submit the malicious path. Given the availability of official patches, the risk can be mitigated by applying the recommended updates.
OpenCVE Enrichment