Impact
The vulnerability permits a remote authenticated attacker to overwrite adjacent memory due to an integer underflow during bounds checking. This memory corruption could lead to unexpected code execution or system compromise, based on the nature of a buffer overwrite. The description does not detail the exact exploitation outcome, but the potential for arbitrary code execution is inferred.
Affected Systems
IBM i operating system versions 7.3, 7.4, 7.5, and 7.6 are affected. The product is IBM:i and the affected releases include 7.3 to 7.6.
Risk and Exploitability
The CVSS score of 3.5 indicates low severity. EPSS is not available, so the likelihood of exploitation is unknown. The vulnerability is not listed in the CISA KEV catalog. Attack requires a remote authenticated session; therefore, only users with valid credentials can exploit it. The exploit could overwrite adjacent memory, potentially allowing arbitrary code execution, but no public proof of concept or alleged exploitation has been reported.
OpenCVE Enrichment