Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to generate a stack-based buffer overflow in the Native IBM i JSSE provider, caused by improper bounds checking during TLS session establishment. A local attacker could overflow a fixed-length buffer and execute arbitrary code on the system or cause the JVM process to crash.
Published: 2026-08-13
Score: 7.3 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a stack‑based buffer overflow in IBM i's native Java Secure Sockets Extension provider, caused by insufficient bounds checking during TLS session establishment. An attacker with local system credentials can trigger the overflow to execute arbitrary code or terminate the Java Virtual Machine. The flaw is mapped to CWE‑787 and is rated as medium severity by CVSS 7.3.

Affected Systems

IBM i versions 7.6, 7.5, 7.4, and 7.3 are affected. Specific patching tracks include PTFs for each release: for 7.6 (SJ11036, SJ11072, SJ11082, SJ11088), for 7.5 (SJ11068, SJ11073, SJ11070, SJ11077, SJ11087), for 7.4 (SJ11071, SJ11069, SJ11076, SJ11086), and for 7.3 (SJ11067, SJ11075, SJ11085).

Risk and Exploitability

The CVSS score of 7.3 indicates a high potential impact, but the entry has no EPSS value and is not listed in CISA’s KEV catalog, suggesting limited public exploitation data. Attack requires local authenticated access, so strong account control is critical. IBM recommends installing the listed PTFs immediately, as the flaw can allow arbitrary code run or cause denial of service through JVM crashes.

Generated by OpenCVE AI on August 13, 2026 at 22:38 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release5770-JV1 PTF Number(s)PTF Download Link(s)7.6SJ11036 SJ11072 SJ11082 SJ11088 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11036 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11072 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11082 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11088 7.5SJ11068 SJ11073 SJ11070 SJ11077 SJ11087 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11068 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11073 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11070 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11077 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11087 7.4SJ11071 SJ11069 SJ11076 SJ11086 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11071 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11069 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11076 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11086 7.3SJ11067 SJ11075 SJ11085 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11067 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11075 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11085 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the IBM i PTFs specified for your release (e.g., SJ11036, SJ11072, SJ11082, SJ11088 for 7.6).
  • If running an unsupported IBM i version, upgrade to a supported, fixed release before applying patches.
  • Limit local user privileges to reduce the window for a local authenticated attacker to exploit the JSSE provider.
  • Monitor JVM logs for crashes or unusual TLS session failures as an indicator of exploitation attempts.

Generated by OpenCVE AI on August 13, 2026 at 22:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to generate a stack-based buffer overflow in the Native IBM i JSSE provider, caused by improper bounds checking during TLS session establishment. A local attacker could overflow a fixed-length buffer and execute arbitrary code on the system or cause the JVM process to crash.
Title IBM i is Affected By Multiple Vulnerabilities in Java Secure Sockets Extension
First Time appeared Ibm
Ibm i
Weaknesses CWE-787
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-13T20:43:37.477Z

Reserved: 2026-07-31T17:24:47.213Z

Link: CVE-2026-18511

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-13T21:17:45.220

Modified: 2026-08-13T21:17:45.220

Link: CVE-2026-18511

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T22:45:03Z

Weaknesses