Impact
IBM i versions 7.3 through 7.6 have a flaw where the WebSocket Origin header is not properly validated, allowing a remote attacker to send data from an untrusted source and cause the system to accept those messages. This results in the disclosure of sensitive information that would normally be protected by the origin check. The weakness is classified as CWE-1385, indicating information exposure through improper validation.
Affected Systems
Affected products include IBM i Release 7.3, 7.4, 7.5, and 7.6 running Navigator for i and Digital Certificate Manager for i. The PTFs that address the issue are SJ11196 and SJ11337 for 7.6; SJ11197 and SJ11336 for 7.5; SJ11200 and SJ11335 for 7.4; SJ11187 and SJ11394 for 7.3; and the related option‑34 updates SJ11377, SJ11376, SJ11375, and SJ11374.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, while the EPSS score of <1% suggests a low probability of exploitation. The vulnerability is not listed in CISA KEV. Exploitation requires network connectivity and the ability to initiate a WebSocket handshake; successful exploitation permits an attacker to read protected data but does not provide arbitrary code execution or privilege escalation.
OpenCVE Enrichment