Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a denial of service as a result of a buffer overflow in a PASE process. An authenticated attacker could leverage this to terminate their own process.
Published: 2026-09-14
Score: 5.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via buffer overflow in a PASE process
Action: Patch
AI Analysis

Impact

The flaw is a buffer overflow in a PASE (Portable Application Service Environment) process on IBM i 7.6, 7.5, 7.4, and 7.3. This overflow can cause a denial of service by terminating the attacker‑controlled process. Because the bug uses a memory buffer incorrectly, an authenticated attacker can exploit it to disrupt the process they own, potentially interrupting critical business functions that rely on that process.

Affected Systems

Affected platforms are IBM i versions 7.6, 7.5, 7.4, and 7.3. The issue is fixed in IBM i Release 5770‑999 through the various PTFs provided: MJ11517 for 7.6, MJ11513 for 7.5, MJ11511 for 7.4, and MJ11509 for 7.3. Users running any of these versions should apply the corresponding patch set. IBM also recommends that users of unsupported versions upgrade to a supported and fixed IBM i release.

Risk and Exploitability

The CVSS score of 5.2 indicates a moderate severity. EPSS information is not available, and the vulnerability is not in the CISA KEV catalog. Exploitation requires the attacker to be authenticated to the system and to have the ability to create or run a PASE process. Because the denial of service is limited to the attacker’s own process, the impact is restricted to service disruption of that process rather than a full system compromise.

Generated by OpenCVE AI on September 15, 2026 at 09:08 UTC.

Remediation

Vendor Solution

IBM i Release5770-999  PTF Number(s)PTF Download Link(s)7.6MJ11517 MJ11513 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ11517 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ11513 7.5MJ11516 MJ11511 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ11516 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ11511 7.4MJ11515 MJ11510 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ11515 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ11510 7.3MJ11514 MJ11509 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ11514 https://www.ibm.com/mysupport/s/fix-information?legacy=MJ11509 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the latest IBM i patch for the current version: download and install MJ11517 for 7.6, MJ11513 for 7.5, MJ11511 for 7.4, or MJ11509 for 7.3 from IBM support.
  • Restart the affected PASE service or reboot the system to ensure the patch takes effect.
  • If using an unsupported IBM i release, upgrade to the latest supported IBM i version that includes the fix.

Generated by OpenCVE AI on September 15, 2026 at 09:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a denial of service as a result of a buffer overflow in a PASE process. An authenticated attacker could leverage this to terminate their own process.
Title IBM i is Affected By Multiple Vulnerabilities in PASE [, ]
First Time appeared Ibm
Ibm i
Weaknesses CWE-787
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 5.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-14T20:59:19.758Z

Reserved: 2026-08-07T15:31:49.343Z

Link: CVE-2026-19280

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-14T21:17:04.627

Modified: 2026-09-14T21:17:04.627

Link: CVE-2026-19280

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T09:15:18Z

Weaknesses