Impact
IBM i version 7.6, 7.5, 7.4 and 7.3 contain a remote buffer overflow that allows an attacker to trigger a denial of service and alter authentication metadata. The buffer overflow occurs when the system processes input from network services without proper bounds checking, leading to crash or modification of critical security state. As a result, an attacker could temporarily deny legitimate users from accessing the system and potentially tamper with authentication credentials or logs.
Affected Systems
The affected modules include Host Servers, Debug Server, Telnet, and DRDA/DDM on IBM i installations running releases 7.6, 7.5, 7.4, or 7.3. The vendor has published specific Program Temporary Fix (PTF) numbers for each subsystem—SJ11101, SJ11102, SJ11103, SJ11104, SJ11100 for Host Servers; SJ10899 for the Debug Server; SJ11022 for Telnet; and SJ10848 for DRDA/DDM. Systems running unsupported versions should upgrade to a supported release with the fixes applied.
Risk and Exploitability
With a CVSS score of 8.2 this vulnerability is classified as high severity. The EPSS score is not available, and the issue is not listed in CISA’s KEV catalog, suggesting no confirmed widespread exploitation yet. Nonetheless, the attack vector is inferred to be remote and involves exploitation of exposed network services. An attacker with network reach to the affected IBM i system can send crafted input to trigger the overflow, causing a service interruption and compromising authentication data. The risk remains significant due to the critical nature of authentication metadata and the potential for denial of service in enterprise environments.
OpenCVE Enrichment