Impact
An integer underflow in IBM i 7.6, 7.5, 7.4, and 7.3 can cause a buffer overflow exploited by an authenticated remote attacker to corrupt system memory, compromising confidentiality and integrity of the affected system.
Affected Systems
IBM i 7.6, 7.5, 7.4, and 7.3 are vulnerable. The vendor recommends applying the PTFs MJ11326 (for 7.6), MJ11327 (for 7.5), MJ11328 (for 7.4), and MJ11329 (for 7.3). Unsupported releases should be upgraded to IBM i 5770‑999.
Risk and Exploitability
The CVSS score of 6.3 reflects moderate impact. The EPSS score of less than 1% indicates a very low probability of exploitation. The flaw is not listed in the CISA KEV catalog. Attacker must have valid credentials and remote access. The risk warrants immediate remediation.
OpenCVE Enrichment