Impact
An integer overflow in NetServer input processing can trigger a server thread exception, causing a temporary denial of service when an authenticated attacker supplies a crafted request. The flaw is a bounds‑checking error (CWE‑190). It does not grant code execution or compromise data confidentiality, and the impact is limited to the availability of the NetServer service while the system remains online.
Affected Systems
The vulnerability affects IBM i releases 7.6, 7.5, 7.4, and 7.3. The corresponding IBM Fix Central packages are MJ10939 for 7.6, MJ10938 for 7.5, MJ10937 for 7.4, and MJ10936 for 7.3, and they should be installed on any affected system.
Risk and Exploitability
The CVSS score of 6.5 classifies the weakness as moderately severe. No EPSS score is available, and the flaw is not listed in CISA’s KEV catalog, indicating a lower likelihood of widespread exploitation. However, because the flaw requires authentication, the risk is real for users who have valid logins. Patching is the recommended mitigation, with monitoring of unauthorized access as a secondary measure.
OpenCVE Enrichment