Impact
An improper bounds check in the IBM i debug server allows a remote authenticated attacker to execute arbitrary code. The flaw permits the attacker to provide input that exceeds expected limits, corrupting memory and enabling execution of malicious instructions. Once exploited, the attacker can gain code execution privileges on the affected system, potentially compromising confidentiality, integrity, and availability of the host and any data it processes.
Affected Systems
The vulnerability exists in IBM i versions 7.6, 7.5, 7.4, and 7.3. Users of these releases are impacted unless they have applied the corresponding IBM Particulate Fixes (PTFs) for each version; support for newer, patched releases is recommended for unsupported versions.
Risk and Exploitability
The CVSS score of 7.6 indicates a high severity level, while the EPSS score is not available, suggesting no current exploitation data but not ruling out future attacks. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, but its nature—remote code execution via an authenticated interface—makes it a high‑risk target. Successful exploitation would allow an attacker with debugging credentials to run arbitrary code on the system, compromising the entire platform.
OpenCVE Enrichment