Impact
The vulnerability is an out‑of‑bounds read in IBM i NetServer that lets a remote attacker read data outside the intended buffer, potentially exposing sensitive information. The flaw is a classic CWE‑125 vulnerability and can lead to information disclosure without authentication.
Affected Systems
IBM i running releases 7.3, 7.4, 7.5 and 7.6 are affected. IBM provides public PTFs (MJ10936 through MJ10939) to address the issue. Users of unsupported releases should upgrade to a supported, fixed version of IBM i.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate risk. EPSS is not available and the vulnerability is not listed in CISA KEV, suggesting a low exploitation probability in the near term. Attackers would likely target the NetServer service over the network, but no publicly disclosed exploit is known and the flaw requires remote access to the affected server.
OpenCVE Enrichment