CVE-2025-3218: IBM i improper certificate validation
IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 is vulnerable to authentication and authorization attacks due to incorrect validation processing in IBM i Netserver. A malicious actor could use the weaknesses, in conjunction with brute force authentication attacks or to bypass authority restrictions, to access the server.
Other sources
IBM i is vulnerable to authentication and authorization attacks due to incorrect validation processing in IBM i Netserver. A malicious actor could use the weaknesses, in conjunction with brute force authentication attacks or to bypass authority restrictions, to access the server.
— IBM
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3218?
CVE-2025-3218 is classified as a significant vulnerability due to the potential for unauthorized access and privilege escalation.
How do I fix CVE-2025-3218?
To fix CVE-2025-3218, apply the latest security patch from IBM for your version of IBM i.
What versions of IBM i are affected by CVE-2025-3218?
CVE-2025-3218 affects IBM i versions 7.2, 7.3, 7.4, 7.5, and 7.6.
What kind of attacks does CVE-2025-3218 enable?
CVE-2025-3218 enables authentication and authorization attacks, including brute force attempts and authority bypass.
Is there a workaround for CVE-2025-3218 if I cannot apply the patch immediately?
There are no specific workarounds recommended for CVE-2025-3218, so applying the patch is strongly advised.