Executive brief
IBM i is an enterprise operating system used to run critical business applications and data storage. An authenticated attacker with FTP access can bypass security controls by sending crafted FTP PORT and EPRT commands, potentially gaining access to internal network services that should be restricted. This allows lateral movement and access to resources an attacker should not reach.
Technical details
A server-side request forgery (SSRF) vulnerability exists in the IBM i FTP service due to improper validation of PORT and EPRT commands. An authenticated attacker over the network can issue these FTP commands to make the FTP service initiate connections to arbitrary internal network services, bypassing firewall and access control restrictions. Patches are available for all affected versions.
Affected products
- IBM i 7.3, 7.4, 7.5, 7.6
Timeline
- 2026-09-18: disclosed
- 2026-09-18: patched: PTF SJ11371 (7.6), SJ11382 (7.5), SJ11383 (7.4), SJ11384 (7.3)