Impact
IBM i Versions 7.6, 7.5, 7.4, and 7.3 contain a heap buffer overflow within NetServer that can be triggered by a remote attacker who is already authenticated. The flaw can lead to the disclosure of sensitive information. It is classified as a buffer overflow (CWE‑787).
Affected Systems
Affected products are IBM i releases 7.6, 7.5, 7.4, and 7.3. For each release the IBM i NetServer PTF that addresses the heap buffer overflow is MJ10939 for 7.6, MJ10938 for 7.5, MJ10937 for 7.4, and MJ10936 for 7.3, all available from IBM's support site.
Risk and Exploitability
The CVSS score of 4.3 indicates a low-level vulnerability in of overall impact and exploitability. The EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting it is not currently widely exploited. However, because the attack requires authentication, a compromised or privileged user could obtain sensitive data. The primary attack vector is remote authenticated access to NetServer services.
OpenCVE Enrichment