Impact
A buffer overflow occurs in a PASE process on IBM i versions 7.6, 7.5, 7.4, and 7.3. The flaw, identified as CWE-125, allows an attacker to overwrite memory bounds and terminate the process that invoked the overflow. The level, affecting only the user’s own process rather than the entire system.
Affected Systems
IBM i platforms running any of the major releases 7.6, 7.5, 7.4, or 7.3 are impacted. The vulnerability resides in the PASE environment and is documented across all these releases. Each major release has specific PTFs (e.g., MJ11517, MJ11513 for 7.6; MJ11516, MJ11511 for 7.5; MJ11515, MJ11510 for 7.4; MJ11514, MJ11509 for 7.3) that remediate the flaw.
Risk and Exploitability
With a CVSS base score of 3.3, the vulnerability is considered low severity. The EPSS score is not available, and it is not listed in the CISA KEV catalog, indicating no known public exploitation. The attack requires the attacker to be authenticated to the IBM i system and to have the ability to launch a PASE process; this is inferred from the description. Once authenticated, the attacker can trigger the overflow to kill only their own process, potentially disrupting services for that account but not granting broader system compromise. The overall risk is moderate, driven primarily by the need for authenticated access and the impact on availability for the affected user.
OpenCVE Enrichment