Impact
An out‑of‑bounds read in the IBM i NetServer component can be triggered by a remote attacker, leading to a denial of service. The affected code fails to check array bounds before accessing memory, which is a classic buffer overread weakness identified as CWE‑125. If an attacker succeeds, the NetServer service will crash, causing service interruption for any applications that rely on it.
Affected Systems
IBM i releases 7.3, 7.4 7.5 and 7.6 are impacted. Patches are available as IBM i PTFs: MJ10936 for 7.3, MJ10937 for 7.4, MJ10938 for 7.5, and MJ10939 for 7.6. Users of unsupported or superseded versions should plan to migrate to a supported and fixed release.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. No EPSS data is published, so the likelihood of exploitation cannot be quantified, but the vulnerability is remotely exploitable via the NetServer interface. The issue is not currently listed in the CISA KEV catalog, and a formal workaround is not offered by IBM. Given the remote nature and the potential for widespread service disruption, administrators should treat it as a moderate‑to‑high risk for environments exposing NetServer to untrusted networks.
OpenCVE Enrichment