Impact
An out-of-bounds read flaw in IBM i 7.6, 7.5, 7.4, and 7.3 allows a remote authenticated attacker to read memory locations that should be inaccessible. This can expose sensitive data that the attacker is not authorized to see, potentially compromising confidentiality of system information.
Affected Systems
IBM i releases 7.3 through 7.6 are affected. All 7.3.x, 7.4.x, 7.5.x, and 7.6.x variants are vulnerable. Patches are available for each release: PTF MJ10971 for 7.3, MJ10972 for 7.4, and MJ10974 for 7.6. Any system running these releases without the latest fixes is susceptible to exploitation.
Risk and Exploitability
The CVSS score of 7.7 indicates a high severity. EPSS is not available and the vulnerability is not listed in CISA KEV. Exploitation requires remote authentication, so a credentialed attacker can potentially pull data over the network once they have valid access. While no widespread exploits are publicly documented, the impact is serious if the flaw is leveraged.
OpenCVE Enrichment