Impact
A buffer overflow in IBM i versions 7.6, 7.5, 7.4, and 7.3 allows a remote authenticated attacker to execute arbitrary code. The flaw is present across several IBM i host services, including Host Servers, Debug Server, Telnet, and DRDA/DDM. An attacker who can authenticate to the system and trigger the overflow can take control of the affected process, potentially compromising the entire platform. The weakness is identified as CWE‑787 – Buffer Overflow, which directly jeopardizes the integrity and availability of the system.
Affected Systems
IBM i platforms running releases 7.6‑SS1, 7.5‑SS1, 7.4‑SS1 and 7.3‑SS1 are affected. For each release, IBM provides specific Product Fix Technology (PTF) numbers to remediate the flaw: Host Servers PTFs include SJ11101 and SJ11097 for 7.6, SJ11102 and SJ11098 for 7.5, SJ11103 and SJ11099 for 7.4, and SJ11104 and SJ11100 for 7.3. Additional PTFs are required for other services: Debug Server requires SJ10899, Telnet requires SJ11022, and DRDA/DDM requires SJ10848.
Risk and Exploitability
The CVSS score of 8.8 indicates very high severity; the flaw can be abused by any authenticated user with sufficient privileges to produce a buffer overflow. Although an EPSS score is not available, the lack of inclusion in the CISA KEV catalog suggests no current public exploits are tracked, but the high severity and confirmed resource for remediation warrant immediate attention. IBM recommends addressing the vulnerability promptly to prevent potential compromise of confidentiality, integrity, and system availability.
OpenCVE Enrichment