Impact
A remote attacker can trigger a byte‑count and element‑count confusion in IBM i’s Java Secure Sockets Extension to obtain sensitive information. The vulnerability is an example of Information Exposure (CWE‑200) and allows reading data that should not be exposed via the affected APIs.
Affected Systems
IBM i 7.3, 7.4, 7.5, and 7.6 are impacted. The specific fix technical maintenance packages for each release are: 7.6 – SJ11036, SJ11072, SJ11082, SJ11088; 7.5 – SJ11068, SJ11073, SJ11070, SJ11077, SJ11087; 7.4 – SJ11071, SJ11069, SJ11076, SJ11086; 7.3 – SJ11067, SJ11075, SJ11085. Applying these PTFs resolves the exposure in the affected Java socket layers.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity for an information disclosure flaw. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that active exploitation may be limited but still possible. The attack vector is likely remote, leveraging the Java Secure Sockets Extension when it is used in network communication. With the current information, the risk primarily involves confidentiality compromise rather than denial of service or denial of access.
OpenCVE Enrichment