Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to a byte-count and element-count confusion.
Published: 2026-08-13
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A remote attacker can trigger a byte‑count and element‑count confusion in IBM i’s Java Secure Sockets Extension to obtain sensitive information. The vulnerability is an example of Information Exposure (CWE‑200) and allows reading data that should not be exposed via the affected APIs.

Affected Systems

IBM i 7.3, 7.4, 7.5, and 7.6 are impacted. The specific fix technical maintenance packages for each release are: 7.6 – SJ11036, SJ11072, SJ11082, SJ11088; 7.5 – SJ11068, SJ11073, SJ11070, SJ11077, SJ11087; 7.4 – SJ11071, SJ11069, SJ11076, SJ11086; 7.3 – SJ11067, SJ11075, SJ11085. Applying these PTFs resolves the exposure in the affected Java socket layers.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate severity for an information disclosure flaw. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that active exploitation may be limited but still possible. The attack vector is likely remote, leveraging the Java Secure Sockets Extension when it is used in network communication. With the current information, the risk primarily involves confidentiality compromise rather than denial of service or denial of access.

Generated by OpenCVE AI on August 13, 2026 at 22:41 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release5770-JV1 PTF Number(s)PTF Download Link(s)7.6SJ11036 SJ11072 SJ11082 SJ11088 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11036 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11072 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11082 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11088 7.5SJ11068 SJ11073 SJ11070 SJ11077 SJ11087 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11068 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11073 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11070 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11077 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11087 7.4SJ11071 SJ11069 SJ11076 SJ11086 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11071 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11069 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11076 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11086 7.3SJ11067 SJ11075 SJ11085 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11067 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11075 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11085 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the IBM i PTFs listed above for the respective release (e.g., SJ11036, SJ11072, SJ11082, SJ11088 for 7.6).
  • Configure network firewalls or IBM i access controls so that only trusted hosts can connect to services that use the Java Secure Sockets Extension, limiting exposure to internal or controlled traffic.
  • Monitor for anomalous or unexpected connections to Java Secure Sockets services and review logs for attempts to manipulate byte or element counts.

Generated by OpenCVE AI on August 13, 2026 at 22:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to a byte-count and element-count confusion.
Title IBM i is Affected By Multiple Vulnerabilities in Java Secure Sockets Extension
First Time appeared Ibm
Ibm i
Weaknesses CWE-200
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-13T20:41:41.526Z

Reserved: 2026-07-28T14:50:07.920Z

Link: CVE-2026-18068

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-13T21:17:44.067

Modified: 2026-08-13T21:17:44.067

Link: CVE-2026-18068

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T00:15:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor