Impact
IBM i versions 7.6, 7.5, 7.4, and 7.3 contain a flaw in the Java Secure Sockets Extension that allows a local attacker to trigger an improper bounds check, which can lead to arbitrary code execution or cause the system to crash. The vulnerability is limited to users who have local access to the affected IBM i operating system and does not provide remote exploitation vectors.
Affected Systems
Affected products are IBM i running versions 7.6, 7.5, 7.4, and 7.3. For each release, IBM has issued a set of patches, including PTFs such as SJ11036, SJ11072, SJ11082, SJ11088 for 7.6, along with corresponding PTFs for the earlier releases. Users running unsupported versions should consider upgrading to a supported, fixed release.
Risk and Exploitability
The CVSS score of 4.5 reflects moderate security risk. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation. The likely attack vector is a local attacker with sufficient privileges to apply patches or execute code on the IBM i system.
OpenCVE Enrichment