CVE-2026-4942
5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Summary
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to send a specifically crafted message and downgrade the Transport Layer Security (TLS) protocol to a version disabled in the server configuration.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| IBM | i | 7.6 | affected |
| IBM | i | 7.5 | affected |
| IBM | i | 7.4 | affected |
| IBM | i | 7.3 | affected |
Weaknesses
- CWE-757: CWE-757 Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.