Impact
IBM Java SDK and Runtime on IBM i allow a remote authenticated attacker to read pointers from Java-controlled addresses without proper validation, potentially enabling the attacker to gain elevated privileges on the operating system. The weakness is a classic example of improper privilege management (CWE-269) and can be leveraged to compromise integrity and availability of the affected platforms. The CVSS score of 8.4 classifies this as a high‑severity vulnerability.
Affected Systems
IBM i versions 7.6, 7.5, 7.4, and 7.3 are affected. IBM recommends applying the specified PTFs: for 7.6 SJ11037, SJ11013, SJ11065, and SJ11078; for 7.5 SJ10990, SJ11014, SJ11042, SJ11066, and SJ11080; for 7.4 SJ11016, SJ11041, SJ11064, and SJ11081; and for 7.3 SJ11040, SJ11063, and SJ11079. Users on older or unsupported releases should upgrade to the latest supported version.
Risk and Exploitability
The vulnerability is listed with a CVSS of 8.4 and currently has no EPSS score available, indicating that publicly available exploitation data is not known. It is not in the CISA KEV catalog. The likely attack vector requires an attacker to be authenticated to the IBM i system; from that standpoint, the attacker could run arbitrary privileged code or modify system state. Because the flaw stems from pointer validation in the Java runtime, exploitation would require carefully crafted Java code that triggers the pointer read. In the absence of a publicly documented exploit, the risk remains primarily theoretical but serious for organizations that run the affected IBM i releases without the available PTFs.
OpenCVE Enrichment