Executive brief
IBM i's Digital Certificate Manager (DCM) is a tool for managing digital certificates used in enterprise systems. A remote authenticated attacker can bypass security restrictions by exploiting improper validation of anti-CSRF tokens, potentially allowing unauthorized access to sensitive data and unauthorized operations on the system.
Technical details
The vulnerability is a Cross-Site Request Forgery (CSRF) bypass due to improper validation of anti-CSRF tokens in IBM i's Digital Certificate Manager. It requires authentication but no user interaction, and affects network-reachable services. An authenticated attacker can craft malicious requests to perform unauthorized operations and access sensitive information (CWE-352). Patches are available for IBM i 7.3, 7.4, 7.5, and 7.6 via PTF numbers SJ10904, SJ10905, SJ10906, and SJ10907 respectively.
Affected products
- IBM IBM i 7.3, 7.4, 7.5, 7.6
Timeline
- 2026-08-13: disclosed
- 2026-08: patched: PTF SJ10907 (7.6), SJ10906 (7.5), SJ10905 (7.4), SJ10904 (7.3)