Impact
The flaw is a buffer overflow in a PASE (Portable Application Service Environment) process on IBM i 7.6, 7.5, 7.4, and 7.3. This overflow can cause a denial of service by terminating the attacker‑controlled process. Because the bug uses a memory buffer incorrectly, an authenticated attacker can exploit it to disrupt the process they own, potentially interrupting critical business functions that rely on that process.
Affected Systems
Affected platforms are IBM i versions 7.6, 7.5, 7.4, and 7.3. The issue is fixed in IBM i Release 5770‑999 through the various PTFs provided: MJ11517 for 7.6, MJ11513 for 7.5, MJ11511 for 7.4, and MJ11509 for 7.3. Users running any of these versions should apply the corresponding patch set. IBM also recommends that users of unsupported versions upgrade to a supported and fixed IBM i release.
Risk and Exploitability
The CVSS score of 5.2 indicates a moderate severity. EPSS information is not available, and the vulnerability is not in the CISA KEV catalog. Exploitation requires the attacker to be authenticated to the system and to have the ability to create or run a PASE process. Because the denial of service is limited to the attacker’s own process, the impact is restricted to service disruption of that process rather than a full system compromise.
OpenCVE Enrichment