Impact
This vulnerability is a race condition that occurs during the WebSocket handshake in IBM i’s Navigator for i and Digital Certificate Manager for i components. A remote attacker who has authenticated credentials can read sensitive data before the handshake finishes. The race condition is identified by CWE‑362 and can expose confidential information such as user should remain protected.
Affected Systems
Affected IBM i releases include 7.6, 7.5, 7.4, and 7.3. Patches are provided for each release and are identified by PTF numbers – for example, 7.6 receives SJ11196 and SJ11337, 7.5 receives SJ11197 and SJ11336, 7.4 receives SJ11200 and SJ11335, and 7.3 receives SJ11187 and SJ11394. IBM recommends upgrading to a supported, patched release if operating on otherwise unsupported versions.
Risk and Exploitability
The CVSS score is 4.2, indicating moderate risk. EPSS indicates a very low exploitation probability (<1%). The vulnerability requires authenticated access to the affected services; thus, an attacker must first compromise valid credentials. While the KEV catalog does not list this vulnerability, the potential confidentiality impact remains significant. IBM strongly recommends addressing the issue now.
OpenCVE Enrichment