Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated attacker to obtain sensitive information in PASE. An attacker could exploit this vulnerability to access information about process they shouldn't be permitted to access.
Published: 2026-09-04
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Information Exposure
Action: Apply Patch
AI Analysis

Impact

An IBM i vulnerability grants an authenticated attacker the ability to read sensitive information about processes in the PASE environment. The flaw allows the attacker to access data on processes they are not permitted to view, exposing potential confidentiality risks. The issue is identified as an instance of sensitive information exposure (CWE-200), indicating that protected data can be disclosed to unauthorized users once authentication is achieved. Lack of publicly reported exploits and the absence of an EPSS score suggest limited known exploitation, and the vulnerability is not listed in CISA's KEV catalog. The CVSS score of 6.5 indicates a moderate severity, and exploitation requires the attacker to have authenticated credentials on the IBM i system, implying that the threat is primarily to users with existing access rights rather than to unauthenticated remote attackers.

Affected Systems

IBM i releases 7.3, 7.4, 7.5 and 7.6 are affected. Each version can be patched using the specific Platform Technical Fix (PTF) numbers: 7.6 requires PTF MJ11365, 7.5 requires MJ11364, 7.4 requires MJ11363, and 7.3 requires MJ11362. Upgrading to IBM i Release5770-999, which includes the fix, is also a viable path for all affected releases.

Risk and Exploitability

With a CVSS base score of 6.5, the vulnerability presents a moderate risk level. The lack of a documented EPSS score and the fact that it is not flagged in KEV imply that no widespread exploitation has been observed. Because the described attack requires authentication and the specific vector (local or remote) is not detailed in the advisory, the most evident risk is to users who already have privileged or valid user credentials on the IBM i platform.

Generated by OpenCVE AI on September 4, 2026 at 19:11 UTC.

Remediation

Vendor Solution

IBM i Release5770-999  PTF Number(s)PTF Download Link(s)7.6MJ11365  https://www.ibm.com/mysupport/s/fix-information?legacy=MJ11365 7.5MJ11364 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ11364 7.4MJ11363 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ11363 7.3MJ11362 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ11362 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the appropriate PTF for your IBM i release: download and apply MJ11365 for 7.6, MJ11364 for 7.5, MJ11363 for 7.4, or MJ11362 for 7.3.
  • Upgrade the system to a supported, fixed version such as IBM i Release5770-999, which incorporates the PTF fix in a single update.
  • Limit and audit user permissions for PASE access, ensuring that no account has unnecessary rights to view other processes or sensitive system data.

Generated by OpenCVE AI on September 4, 2026 at 19:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.6:*:*:*:*:*:*:*

Fri, 04 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated attacker to obtain sensitive information in PASE. An attacker could exploit this vulnerability to access information about process they shouldn't be permitted to access.
Title IBM i is Affected By Sensitive Information Exposure Vulnerability in PASE []
First Time appeared Ibm
Ibm i
Weaknesses CWE-200
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-04T16:45:07.247Z

Reserved: 2026-08-04T19:28:49.757Z

Link: CVE-2026-18887

cve-icon Vulnrichment

Updated: 2026-09-04T16:44:28.791Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-04T16:17:21.393

Modified: 2026-09-08T21:36:35.087

Link: CVE-2026-18887

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-05T00:00:06Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor