Executive brief
IBM i operating systems are vulnerable to a security flaw that allows a remote attacker to force the system to use outdated and insecure encryption protocols. By sending a specially crafted message, an attacker can bypass modern security settings and downgrade the connection to a version of TLS that was previously disabled. This could allow an attacker to intercept or eavesdrop on sensitive communications that were intended to be secure.
Technical details
A vulnerability in IBM i (versions 7.3 through 7.6) allows for a TLS protocol downgrade attack (CWE-757). A remote, unauthenticated attacker can send a specifically crafted message during the handshake process to force the server to negotiate a TLS version that has been explicitly disabled in the system configuration. While the attack complexity is high, successful exploitation allows the attacker to potentially decrypt or intercept traffic by forcing the use of weaker, deprecated cryptographic protocols. IBM has released Program Temporary Fixes (PTFs) to address this issue across all affected versions.
Affected products
- IBM i 7.6, 7.5, 7.4, 7.3
Timeline
- 2026-07-02: disclosed: Initial publication by IBM
- 2026-07-17: advisory: NVD publication date