Impact
IBM i must not have vulnerabilities that allow arbitrary code execution. The flaw is a stack‑based buffer overflow in the debug server that lets a remote attacker execute arbitrary code, classified as CWE‑787 and capable of providing full control over the affected system if exploited.
Affected Systems
Affected are IBM i releases 7.6, 7.5, 7.4, and 7.3. IBM publishes specific PTFs for each release (SJ10899 for 7.6, SJ10903 for 7.5, SJ10915 for 7.4, and SJ10916 for 7.3). Users on unsupported or older versions are urged to upgrade to a supported, patched release. The debugging service is the component at risk, so only systems that expose the debug server are exposed.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity. Although EPSS is not available and the vulnerability is not listed in CISA KEV, the underlying stack overflow can be triggered remotely. Likely, an attacker communicates with the debug server over a network port and sends crafted payloads to trigger the overflow. Organizations should prioritize patching or disabling the service to mitigate this high‑risk, easily exploitable flaw.
OpenCVE Enrichment