Impact
A stack-based buffer overflow in the debug server of IBM i allows a remote authenticated attacker to cause a denial of service. An attacker who can authenticate to the debug service can trigger a crash that interrupts system availability. The problem is not an elevation of privilege; it is purely an availability issue, reflected in a CVSS score of 4.3.
Affected Systems
IBM i versions 7.6, 7.5, 7.4, and 7.3 are affected. The fix is distributed through PTFs SJ11305 for 7.6, SJ11306 for 7.5, SJ11307 for 7.4, and SJ11308 for 7.3, and the release 5770‑SS1.
Risk and Exploitability
The CVSS score of 4.3 suggests low to moderate severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog, indicating that widespread exploitation is not currently documented. The attack requires the attacker to have valid credentials to the debug server, so the risk is limited to environments that expose that service and have in‑place authentication mechanisms. If those conditions are met, the attacker can interrupt operations by inducing a stack overflow that terminates the debug server process.
OpenCVE Enrichment