CVE-2025-36119
7.1IBM · i
IBM i versions 7.3 through 7.6 are susceptible to a web session hijacking vulnerability in Digital Certificate Manager for i that allows authenticated users to gain unauthorized administrative access.
Executive summary
A web session hijacking vulnerability in IBM i allows authenticated users to escalate privileges to administrator status, posing a significant risk to system integrity.
Vulnerability
The flaw is an authentication bypass via session hijacking (CWE-290) within the Digital Certificate Manager (DCM) component. Any authenticated user can exploit this vulnerability to perform administrative actions without holding the necessary privileges.
Business impact
Successful exploitation allows a standard authenticated user to assume administrative control over the Digital Certificate Manager, which is critical for managing system security and cryptographic identities. This could lead to unauthorized modification of system certificates, potential interception of secure traffic, and a total compromise of the affected administrative interface. With a CVSS score of 7.1, this vulnerability represents a high-severity risk to system confidentiality and integrity.
Remediation
Immediate Action: Apply the vendor-provided Program Temporary Fix (PTF) for your specific IBM i release: 7.6 (SJ06558), 7.5 (SJ06557), 7.4 (SJ06552), or 7.3 (SJ06550).
Proactive Monitoring: Audit access logs for the Digital Certificate Manager for i (DCM) to identify anomalous administrative actions originating from non-administrative user accounts.
Compensating Controls: Restrict network access to the DCM web interface to known, trusted administrative workstations only to minimize the exposure of this management interface.
Exploitation status
Public Exploit Available: No (exploit_available: unknown)
Analyst recommendation
This vulnerability presents a clear path for privilege escalation that could jeopardize the security of the entire IBM i environment. Administrators should verify their current version against the affected list and prioritize the installation of the specified PTFs during the next maintenance window. Failure to address this flaw leaves the administrative functions of the Digital Certificate Manager exposed to any internal user with standard access.