Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an improper buffer write.
Published: 2026-08-13
Score: 4.8 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper buffer write flaw (CWE‑787) in IBM i can be triggered by a remote attacker and leads to a system crash or reset, causing denial of service. The vulnerability does not provide privilege escalation or data disclosure but can interrupt critical business processes if the affected services are exposed to external connections.

Affected Systems

IBM i releases 7.6, 7.5, 7.4, and 7.3 are affected. The official corrective measures are the PTFs listed for each release: for 7.6 – SJ11037, SJ11013, SJ11065, SJ11078; for 7.5 – SJ10990, SJ11014, SJ11042, SJ11066, SJ11080; for 7.4 – SJ11016, SJ11041, SJ11064, SJ11081; for 7.3 – SJ11040, SJ11063, SJ11079.

Risk and Exploitability

With a CVSS score of 4.8 the severity is moderate. The EPSS score is not available, and the vulnerability is not currently listed in CISA KEV, indicating no known widespread exploitation. The attack vector is remote, likely through networked Java services that run on IBM i. Because exploitation does not require local privileges, any host exposed to the network is potentially at risk.

Generated by OpenCVE AI on August 13, 2026 at 22:43 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release5770-JV1 PTF Number(s)PTF Download Link(s)7.6SJ11037 SJ11013 SJ11065 SJ11078 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11037 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11013 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11065 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11078 7.5SJ10990 SJ11014 SJ11042 SJ11066 SJ11080 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10990 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11014 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11042 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11066 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11080 7.4SJ11016 SJ11041 SJ11064 SJ11081 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11016 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11041 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11064 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11081 7.3SJ11040 SJ11063 SJ11079 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11040 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11063 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11079 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the IBM PTFs for your IBM i release (e.g., SJ11037, SJ11013, SJ11065, SJ11078 for 7.6).
  • Upgrade the system to the latest supported IBM i release if running an unsupported version.
  • Restrict external access to Java runtime services to limit exposure to the buffer write flaw.

Generated by OpenCVE AI on August 13, 2026 at 22:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an improper buffer write.
Title IBM i Is Affected By Multiple Vulnerabilities in IBM Java SDK and IBM Java Runtime
First Time appeared Ibm
Ibm i
Weaknesses CWE-787
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-13T20:38:14.990Z

Reserved: 2026-07-25T22:19:23.735Z

Link: CVE-2026-17476

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-13T21:17:43.193

Modified: 2026-08-13T21:17:43.193

Link: CVE-2026-17476

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T22:45:03Z

Weaknesses