Impact
A buffer overflow flaw in IBM i allows a remote authenticated attacker to access sensitive information. The vulnerability arises from insufficient bounds checking when processing data in the Host Servers, Debug Server, Telnet, and DRDA/DDM components. If successfully exploited, an attacker can read memory contents that may contain confidential data, though the description does not state that arbitrary code execution is achieved.
Affected Systems
Affected products are IBM i releases 7.3 through 7.6, covering the Host Servers, Debug Server (7.6), Telnet (7.6), and DRDA/DDM (7.6). IBM publishes specific PTFs—SJ11101 to SJ11104 for the host servers, SJ10899 for the debug server, SJ11022 for Telnet, and SJ10848 for DRDA/DDM—each addressing this buffer overflow. These updates target the older 7.3, 7.4, 7.5, and 7.6 releases, which are still supported but must be patched to prevent the information leakage.
Risk and Exploitability
The CVSS score is 5.3, indicating moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been observed in widespread exploitation. The flaw requires the attacker to be authenticated to the affected IBM i system to trigger the buffer overflow. Despite the moderate CVSS, the potential for data exposure warrants immediate remediation. The vulnerability is a classic buffer overflow (CWE‑787) and should be mitigated by applying the vendor-supplied patches.
OpenCVE Enrichment