Impact
A heap‑based buffer overflow in IBM i versions 7.6, 7.5, 7.4, and 7.3 allows a remote authenticated attacker to execute arbitrary code. The flaw can compromise data confidentiality, integrity, and availability, providing the attacker with unconstrained control over the affected system. The CVSS score of 8.8 reflects a high severity of this issue.
Affected Systems
IBM i 7.6, 7.5, 7.4, and 7.3 are impacted. IBM has supplied specific PTFs to address the flaw: MJ11019 for 7.6, MJ11050 for 7.5, MJ11051 for 7.4, and MJ11052 for 7.3. Users of unsupported versions should upgrade to a supported and fixed release.
Risk and Exploitability
The CVSS score denotes a high severity, but no EPSS score is available. The vulnerability is not listed in the CISA KEV catalog, indicating no publicly known widespread exploitation at this time. A probable attack vector involves a remote authenticated interaction with the system, requiring valid credentials to leverage the buffer overflow and run code.
OpenCVE Enrichment