Impact
The vulnerability is an out-of-bounds read in the NetServer component of IBM i. A remote attacker who can reach the NetServer network service may trigger the read and retrieve arbitrary data from memory, potentially exposing sensitive configuration or authentication information. The weakness corresponds to CWE‑125 and represents a medium‑severity confidentiality breach.
Affected Systems
Products affected are IBM i releases 7.6, 7.5, 7.4, and 7.3 on supported IBM hardware platforms. The fix is provided through PTFs MJ10939, MJ10938, MJ10937, and MJ10936, respectively. No other versions or platforms are noted as impacted.
Risk and Exploitability
The CVSS score 6.5 indicates medium severity, reflecting that remote access to NetServer is required but no code execution is needed. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, suggesting limited or no current exploitation in the wild. The likely attack vector is remote via the NetServer network service; an attacker may exploit the flaw if the service is reachable from the network.
OpenCVE Enrichment