Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service and obtain sensitive information due to an out-of-bounds read.
Published: 2026-08-19
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an out‑of‑bounds read that can be triggered by a remote authenticated attacker. When exploited it can cause a denial of service and allow the attacker to read data outside the intended memory buffer, potentially revealing sensitive information stored on the system.

Affected Systems

The defect is present in IBM i versions 7.6, 7.5, 7.4 and 7.3. The fix is distributed as PTFs SJ11150, SJ11149, SJ11148 and SJ11147 respectively for each version, all included in the IBM i Release5770‑SS1 update set.

Risk and Exploitability

With a CVSS score of 5.4 the vulnerability is classified as moderate. The absence of an EPSS score makes the exploitation probability uncertain, but the need for remote authentication reduces the risk to attackers who have compromised credentials. The issue is not listed in the CISA KEV catalog, suggesting no known active exploits. Prompt application of the recommended PTFs is advised to eliminate the vulnerability.

Generated by OpenCVE AI on August 20, 2026 at 11:05 UTC.

Remediation

Vendor Solution

IBM i Release5770-SS1  PTF Number(s)PTF Download Link(s)7.6SJ11150 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11150 7.5SJ11149 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11149 7.4SJ11148 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11148 7.3SJ11147 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11147 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Install the IBM i Release5770‑SS1 PTF package, applying SJ11150 for 7.6, SJ11149 for 7.5, SJ11148 for 7.4 and SJ11147 for 7.3 as provided in the IBM support references.
  • Restart the affected IBM i subsystem or the relevant services so that the new PTFs take effect.
  • If the patch cannot be applied immediately, disable or restrict remote authentication on the IBM i system to prevent authenticated attackers from exploiting the vulnerability until the fix is applied.

Generated by OpenCVE AI on August 20, 2026 at 11:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service and obtain sensitive information due to an out-of-bounds read.
Title IBM i Denial of Service
First Time appeared Ibm
Ibm i
Weaknesses CWE-125
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-20T16:27:37.115Z

Reserved: 2026-07-24T10:12:42.134Z

Link: CVE-2026-17015

cve-icon Vulnrichment

Updated: 2026-08-20T16:24:36.324Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T21:16:54.143

Modified: 2026-08-24T19:35:08.013

Link: CVE-2026-17015

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T11:15:03Z

Weaknesses