Impact
The vulnerability is an out‑of‑bounds write within the NetServer component of IBM i, discovered in versions 7.3 through 7.6. A malicious remote actor could trigger the flaw and cause a denial of service by corrupting memory, leading to crashes or unresponsive services. The flaw is classified as CWE‑787, indicating improper bounds checking during memory operations. The high CVSS score of 8.6 reflects the significant impact on availability.
Affected Systems
Affected are IBM i releases 7.3, 7.4, 7.5, and 7.6. For each release, IBM has issued a PTF: 7.6MJ10939 for 7.6, 7.5MJ10938 for 7.5, 7.4MJ10937 for 7.4, and 7.3MJ10936 for 7.3. These patches address the NetServer out‑of‑bounds write and restore normal function.
Risk and Exploitability
The stated CVSS of 8.6 signals a high‑severity risk. EPSS is not available, so the current exploit probability cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog, indicating no known active exploitation. Attackers would need to reach the NetServer port from the network and trigger the memory overwrite; no local privilege escalation or authentication is required, making it feasible for a remote attacker. The effect is to disrupt service availability on the affected IBM i system.
OpenCVE Enrichment