Impact
The vulnerability in IBM i versions 7.3 through 7.6 allows a remote authenticated attacker to read sensitive data through an out‑of‑bounds read. The issue resides in the NetServer component and could lead to disclosure of confidential information, compromising data confidentiality. The weakness is categorized as an out‑of‑bounds read (CWE‑125).
Affected Systems
Affected products include IBM i releases 7.3, 7.4, 7.5, and 7.6. Specific versions such as 7.3.0, 7.4.0, 7.5.0, and 7.6.0 are impacted. IBM has published PTFs for each release – MJ10936 for 7.3, MJ10937 for 7.4, MJ10938 for 7.5, and MJ10939 for 7.6.
Risk and Exploitability
The CVSS score is 5.4, indicating medium severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. The description indicates that a remote authenticated attacker can exploit the flaw, so the attack vector is remote authenticated. While no public exploit is known, a compromised user credential or privileged access to NetServer could be used to read sensitive data. The moderate risk coupled with potential for data exposure warrants immediate attention.
OpenCVE Enrichment