Impact
A remote attacker can trigger a buffer overflow in IBM i versions 7.6, 7.5, 7.4, and 7.3, leading to a denial of service of the HTTP server. The vulnerability is a classic out‑of‑bounds write (CWE‑787) that corrupts memory and causes the service to crash. The impact is the loss of availability of the HTTP service for legitimate users, potentially affecting critical business functions that rely on IBM i web services.
Affected Systems
The affected systems are IBM i releases 7.6, 7.5, 7.4, and 7.3. IBM provides specific PTFs for each release: SJ10845 for 7.6, SJ10844 for 7.5, SJ10843 for 7.4, and SJ10842 for 7.3. Users on these releases should update to the latest fix package or, if running a non‑supported version, upgrade to a supported, patched release per IBM recommendations.
Risk and Exploitability
The CVSS score of 8.2 indicates a high severity vulnerability. The EPSS score is not available, so the current quantified likelihood of exploitation is unknown, but the lack of a KEV listing suggests no confirmed exploits are publicly known yet. The likely attack vector is remote, via the HTTP server, with no authentication required to send the malformed request that triggers the buffer overflow. Given the high CVSS and the nature of the flaw, the risk of an active exploitation is significant until the patch is applied.
OpenCVE Enrichment