Impact
The vulnerability is an out‑of‑bounds read that can be triggered by a remote authenticated attacker. When exploited it can cause a denial of service and allow the attacker to read data outside the intended memory buffer, potentially revealing sensitive information stored on the system.
Affected Systems
The defect is present in IBM i versions 7.6, 7.5, 7.4 and 7.3. The fix is distributed as PTFs SJ11150, SJ11149, SJ11148 and SJ11147 respectively for each version, all included in the IBM i Release5770‑SS1 update set.
Risk and Exploitability
With a CVSS score of 5.4 the vulnerability is classified as moderate. The absence of an EPSS score makes the exploitation probability uncertain, but the need for remote authentication reduces the risk to attackers who have compromised credentials. The issue is not listed in the CISA KEV catalog, suggesting no known active exploits. Prompt application of the recommended PTFs is advised to eliminate the vulnerability.
OpenCVE Enrichment