Impact
IBM i releases 7.6, 7.5, 7.4, and 7.3 contain an integer underflow that can be triggered by a remote attacker. The flaw can cause a denial of service and allow the attacker to read sensitive data. This flaw involves CWE‑125 and CWE‑191 and compromises both availability and confidentiality.
Affected Systems
IBM i releases 7.6, 7.5, 7.4, and 7.3 are vulnerable, as identified by the IBM i PTFs MJ10909, MJ10863, MJ10862, and MJ10861, respectively. All affected installations should apply the corresponding PTF or upgrade to a supported, fixed release.
Risk and Exploitability
The CVSS score of 8.2 indicates high severity. EPSS score is less than 1%, which suggests a very low but non‑zero likelihood of exploitation, and the issue is not currently listed in the CISA KEV catalog. However, the flaw can be remotely exploited to disrupt services and potentially expose confidential data, involving both integer underflow (CWE‑125) and signed integer arithmetic failure (CWE‑191). Immediate patching is recommended to mitigate exploit risk.
OpenCVE Enrichment