Impact
The vulnerability is an out‑of‑bounds write in the IBM i Java Secure Sockets Extension, allowing an attacker with local access to write beyond allocated memory boundaries and execute arbitrary code. This can compromise the entire system, giving the attacker read, modify and execute capabilities, effectively overriding system integrity and potentially compromising other services.
Affected Systems
IBM i, versions 7.3 through 7.6, are affected. Specific PTFs are provided for each release: for 7.6, PTFs SJ11036, SJ11072, SJ11082 and SJ11088; for 7.5, SJ11068, SJ11073, SJ11070, SJ11077 and SJ11087; for 7.4, SJ11071, SJ11069, SJ11076 and SJ11086; for 7.3, SJ11067, SJ11075 and SJ11085. All users of these releases, especially those still on unsupported or legacy lines, need to apply these fixes or migrate to a supported release.
Risk and Exploitability
The CVSS score of 8.8 classifies the issue as high severity. Although EPSS is not available, the lack of a publicly known exploit does not diminish the risk; local actors could leverage the vulnerability to compromise the system. The vulnerability is not currently listed CISA KEV catalog, but its impact and high score warrant immediate attention. The attack vector is local, as the description states a local attacker can trigger the out‑of‑bounds write by interacting with the vulnerable component. No public workaround exists, so applying the listed PTFs is the only mitigation.
OpenCVE Enrichment