Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary code due to an out-of-bounds write.
Published: 2026-08-13
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an out‑of‑bounds write in the IBM i Java Secure Sockets Extension, allowing an attacker with local access to write beyond allocated memory boundaries and execute arbitrary code. This can compromise the entire system, giving the attacker read, modify and execute capabilities, effectively overriding system integrity and potentially compromising other services.

Affected Systems

IBM i, versions 7.3 through 7.6, are affected. Specific PTFs are provided for each release: for 7.6, PTFs SJ11036, SJ11072, SJ11082 and SJ11088; for 7.5, SJ11068, SJ11073, SJ11070, SJ11077 and SJ11087; for 7.4, SJ11071, SJ11069, SJ11076 and SJ11086; for 7.3, SJ11067, SJ11075 and SJ11085. All users of these releases, especially those still on unsupported or legacy lines, need to apply these fixes or migrate to a supported release.

Risk and Exploitability

The CVSS score of 8.8 classifies the issue as high severity. Although EPSS is not available, the lack of a publicly known exploit does not diminish the risk; local actors could leverage the vulnerability to compromise the system. The vulnerability is not currently listed CISA KEV catalog, but its impact and high score warrant immediate attention. The attack vector is local, as the description states a local attacker can trigger the out‑of‑bounds write by interacting with the vulnerable component. No public workaround exists, so applying the listed PTFs is the only mitigation.

Generated by OpenCVE AI on August 13, 2026 at 21:23 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release5770-JV1 PTF Number(s)PTF Download Link(s)7.6SJ11036 SJ11072 SJ11082 SJ11088 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11036 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11072 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11082 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11088 7.5SJ11068 SJ11073 SJ11070 SJ11077 SJ11087 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11068 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11073 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11070 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11077 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11087 7.4SJ11071 SJ11069 SJ11076 SJ11086 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11071 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11069 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11076 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11086 7.3SJ11067 SJ11075 SJ11085 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11067 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11075 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11085 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the IBM i patch set for your release: for 7.6 use PTFs SJ11036, SJ11072, SJ11082 and SJ11088; for 7.5 use SJ11068, SJ11073, SJ11070, SJ11077 and SJ11087; for 7.4 use SJ11071, SJ11069, SJ11076 and SJ11086; for 7.3 use SJ11067, SJ11075 and SJ11085.
  • If your IBM i installation is unsupported, upgrade to a supported and patched release of IBM i.
  • Monitor the system for anomalous behavior and validate the patch has protected the affected code paths after deployment.

Generated by OpenCVE AI on August 13, 2026 at 21:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary code due to an out-of-bounds write.
Title IBM i is Affected By Multiple Vulnerabilities in Java Secure Sockets Extension
First Time appeared Ibm
Ibm i
Weaknesses CWE-787
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-13T19:54:29.760Z

Reserved: 2026-07-24T11:19:51.070Z

Link: CVE-2026-17029

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-13T20:17:17.840

Modified: 2026-08-13T20:36:48.443

Link: CVE-2026-17029

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T21:30:11Z

Weaknesses