Impact
An authenticated user can upload files with Navigator for i that bypass intended configuration checks, placing files in locations that should be prohibited. The flaw is a path traversal style weakness (CWE-22) that allows file creation in unintended directories. Based on the description, it is inferred that an attacker could place malicious code or data in protected parts of the system, which would affect integrity and could potentially compromise confidentiality.
Affected Systems
IBM i releases 7.3, 7.4, 7.5, and 7.6 are affected when running the Navigator for i and Digital Certificate Manager for i. PTFs that address the flaw include SJ11187/SJ11394 for 7.3, SJ11200/SJ11335 for 7.4, SJ11197/SJ11336 for 7.5, and SJ11196/SJ11337 for 7.6.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. The exploitation route is a remote authenticated attack that leverages the Navigator interface; it requires valid credentials but otherwise does not need additional privileges beyond what the user already has. Because the flaw is limited to users who already have upload rights, the risk is lower than a privilege‑escalation or code‑execution flaw; however, it remains actionable for a malicious insider or a compromised user, as inferred from the attack requirements.
OpenCVE Enrichment