Impact
The vulnerability is a buffer overflow that occurs when an authenticated attacker opens a PASE process on IBM i 7.6, 7.5, 7.4, or 7.3. The overflow corrupts the stack, causing the offending process to terminate. The exploit’s impact is confined to the attacker‑controlled process, leading only to a local denial of service.
Affected Systems
IBM i releases 7.6, 7.5, 7.4, and 7.3 are affected by this flaw. Each release has dedicated patches: for 7.6 – MJ11517 and MJ11513; for 7.5 – MJ11516 and MJ11511; for 7.4 – MJ11515 and MJ11510; for 7.3 – MJ11514 and MJ11509. Unsupported or older releases should be upgraded to the latest supported IBM i release that contains the fix.
Risk and Exploitability
The CVSS score of 5.2 indicates moderate severity, and the EPSS score of less than 1 % suggests a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is launching a malicious PASE process as an authenticated user; this inference comes from the requirement for authentication and the description of a PASE process. Exploitation causes only the attacker’s own process to fail, without affecting other processes or the overall system.
OpenCVE Enrichment