Executive brief
IBM Navigator for i is a web-based administrative and operational interface for IBM i systems used to manage enterprise server configurations and operations. A remote attacker without authentication can bypass session IP binding protections to gain unauthorized access to sensitive information, potentially allowing them to view or manipulate confidential system data and administrative functions.
Technical details
IBM i Navigator for i is vulnerable to an authentication bypass (CWE-290) via improper session IP binding validation. The vulnerability allows a remote, unauthenticated attacker to obtain sensitive information by spoofing or bypassing IP-based session binding mechanisms. The attack requires no authentication, user interaction, or special privileges, making it easily accessible over the network. An attacker can exploit this to assume the identity of legitimate sessions and access confidential data. IBM has released PTF patches for IBM i 7.3, 7.4, 7.5, and 7.6 addressing this vulnerability.
Affected products
- IBM i 7.6 7.6
- IBM i 7.5 7.5
- IBM i 7.4 7.4
- IBM i 7.3 7.3
Timeline
- 2026-09-14: disclosed