Impact
An authenticated attacker can leverage a buffer overflow (CWE‑125) in a PASE process on IBM i versions 7.6, 7.5, 7.4, and 7.3 to overwrite memory bounds. The overflow can terminate the process that invoked it, but the impact is confined to that process, not the entire system. The flaw does not provide an avenue for broader system compromise; it simply disrupts availability for the affected account.
Affected Systems
IBM i platforms running any of the major releases 7.6, 7.5, 7.4, or 7.3 are impacted. The vulnerability resides in the PASE process. Each major release has specific PTFs (e.g., MJ11517, MJ11513 for 7.6; MJ11516, MJ11511 for 7.5; MJ11515, MJ11510 for 7.4; MJ11514, MJ11509 for 7.3) that remediate the flaw.
Risk and Exploitability
With a CVSS base score of 3.3, the vulnerability is classified as low severity. The EPSS score is < 1%, indicating an extremely low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. An authenticated attacker who can launch a PASE process has the ability to trigger a buffer overflow (CWE‑125) that causes termination of the invoked process, resulting in a denial of service that is limited to that account and does not compromise the broader system. Because the attacker must have valid credentials and the impact is confined to a single process, the overall risk remains low.
OpenCVE Enrichment