Impact
The vulnerability is a stack‑based buffer overflow in IBM i's native Java Secure Sockets Extension provider, caused by insufficient bounds checking during TLS session establishment. An attacker with local system credentials can trigger the overflow to execute arbitrary code or terminate the Java Virtual Machine. The flaw is mapped to CWE‑787 and is rated as medium severity by CVSS 7.3.
Affected Systems
IBM i versions 7.6, 7.5, 7.4, and 7.3 are affected. Specific patching tracks include PTFs for each release: for 7.6 (SJ11036, SJ11072, SJ11082, SJ11088), for 7.5 (SJ11068, SJ11073, SJ11070, SJ11077, SJ11087), for 7.4 (SJ11071, SJ11069, SJ11076, SJ11086), and for 7.3 (SJ11067, SJ11075, SJ11085).
Risk and Exploitability
The CVSS score of 7.3 indicates a high potential impact, but the entry has no EPSS value and is not listed in CISA’s KEV catalog, suggesting limited public exploitation data. Attack requires local authenticated access, so strong account control is critical. IBM recommends installing the listed PTFs immediately, as the flaw can allow arbitrary code run or cause denial of service through JVM crashes.
OpenCVE Enrichment