Executive brief
IBM i is an enterprise operating system for IBM Power servers used to run mission-critical business applications and databases. A path traversal vulnerability in the SQL component allows authenticated remote attackers to bypass file access controls and read or modify arbitrary objects on the system, potentially compromising sensitive business data and system integrity.
Technical details
A path traversal vulnerability (CWE-22) in IBM i SQL allows an authenticated remote attacker to access arbitrary objects outside intended directory restrictions. The vulnerability requires network access and authenticated credentials (PR:L), with medium attack complexity (AC:H), but can impact confidentiality, integrity, and availability across system scope (S:C). An attacker can exploit this to read sensitive database objects, modify system files, or achieve privilege escalation. Patches are available as PTFs for all affected versions: 7.6 (SJ10871), 7.5 (SJ10835), 7.4 (SJ10840), and 7.3 (SJ10841).
Affected products
- IBM i 7.3, 7.4, 7.5, 7.6
Timeline
- 2026-08-13: disclosed
- patched: PTFs available for all affected versions