Impact
An improper buffer write flaw (CWE‑787) in IBM i can be triggered by a remote attacker and leads to a system crash or reset, causing denial of service. The vulnerability does not provide privilege escalation or data disclosure but can interrupt critical business processes if the affected services are exposed to external connections.
Affected Systems
IBM i releases 7.6, 7.5, 7.4, and 7.3 are affected. The official corrective measures are the PTFs listed for each release: for 7.6 – SJ11037, SJ11013, SJ11065, SJ11078; for 7.5 – SJ10990, SJ11014, SJ11042, SJ11066, SJ11080; for 7.4 – SJ11016, SJ11041, SJ11064, SJ11081; for 7.3 – SJ11040, SJ11063, SJ11079.
Risk and Exploitability
With a CVSS score of 4.8 the severity is moderate. The EPSS score is not available, and the vulnerability is not currently listed in CISA KEV, indicating no known widespread exploitation. The attack vector is remote, likely through networked Java services that run on IBM i. Because exploitation does not require local privileges, any host exposed to the network is potentially at risk.
OpenCVE Enrichment