Executive brief
IBM i's Digital Certificate Manager (DCM) component is vulnerable to a path traversal attack that allows authenticated remote users to delete arbitrary files on the system. This could lead to unauthorized file deletion, service disruption, or system compromise depending on which files are targeted.
Technical details
This is a path traversal vulnerability (CWE-22) in IBM i's Digital Certificate Manager that permits authenticated remote attackers to delete arbitrary files by manipulating file path parameters. The vulnerability requires authentication and network access, with no user interaction needed. An attacker with valid credentials can exploit insufficient pathname validation to traverse directory boundaries and delete files outside intended restrictions. IBM has released Platform Technical Fixes (PTFs) for affected versions 7.3 through 7.6; systems should be patched immediately.
Affected products
- IBM IBM i 7.3, 7.4, 7.5, 7.6
Timeline
- 2026-08-13: disclosed
- 2026-08-13: patched: PTFs available for versions 7.3–7.6