Impact
The vulnerability is a classic buffer overflow in IBM i releases 7.6, 7.5, 7.4, and 7.3 that allows a remote attacker to execute arbitrary code. This weakness can be triggered through the host server subsystem and also via auxiliary services such as the debug server, telnet, and DRDA/DDM interfaces, potentially giving the attacker full control over the affected systems.
Affected Systems
IBM i 7.6 (Release5770-SS1), 7.5, 7.4, and 7.3 are impacted. The known fix package track numbers (PTFs) include SJ11101, SJ11097, SJ11098, SJ11099, SJ11100 for the host server; SJ10899 for the debug server; SJ11022 for telnet; and SJ10848 for DRDA/DDM.
Risk and Exploitability
The CVSS score of 8.1 classifies this as high severity, and while a current EPSS score is unavailable, the lack of KEV listing does not negate the critical nature of the flaw. Attackers can exploit the buffer overflow remotely without authentication, leading to arbitrary code execution, data theft, and system compromise. No public exploit exists yet, but the high CVSS and the nature of the vulnerability suggest that exploitation probability is significant enough to warrant immediate action.
OpenCVE Enrichment