IBM InfoSphere Data Replication VSAM for z/OS Remote Source 11.4 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local user with access to the files storing CECSUB or CECRM on the container could overflow the buffer and execute arbitrary code on the system.
Advisories

No advisories yet.

Fixes

Solution

Resolved in APAR PH67757. Available as version is v11.4.0.22 for VSAM Remote source x86 container on fix central. VSAM_Remote_Source_114_Linux_x86.tar


Workaround

No workaround given by the vendor.

History

Tue, 07 Oct 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 07 Oct 2025 17:45:00 +0000

Type Values Removed Values Added
Description IBM InfoSphere Data Replication VSAM for z/OS Remote Source 11.4 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local user with access to the files storing CECSUB or CECRM on the container could overflow the buffer and execute arbitrary code on the system.
Title IBM InfoSphere Data Replication VSAM for z/OS Remote Source code execution
First Time appeared Ibm
Ibm infosphere Data Replication
Weaknesses CWE-119
CPEs cpe:2.3:a:ibm:infosphere_data_replication:11.4:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm infosphere Data Replication
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2025-10-08T03:55:22.946Z

Reserved: 2025-04-15T21:16:20.813Z

Link: CVE-2025-36156

cve-icon Vulnrichment

Updated: 2025-10-07T18:12:54.154Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-10-07T18:15:59.167

Modified: 2025-10-08T19:38:09.863

Link: CVE-2025-36156

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.