Executive brief
IBM i is a business operating system used to run critical enterprise applications and services. An out-of-bounds read vulnerability in the NetServer component could allow remote attackers to access sensitive information stored in system memory without authentication. This could expose confidential business data, customer information, or system credentials.
Technical details
The vulnerability is an out-of-bounds read (CWE-125) in IBM i's NetServer component that allows a remote, unauthenticated attacker to read memory beyond allocated buffer boundaries. The flaw is in network-reachable code with no authentication or user interaction required. By sending specially crafted network requests, an attacker can leak sensitive information from process memory including credentials, encryption keys, or other confidential data. IBM has released PTF MJ10939 for IBM i 7.6 and corresponding patches for 7.5, 7.4, and 7.3 to address this issue.
Affected products
- IBM IBM i 7.3, 7.4, 7.5, 7.6
Timeline
- 2026-08-13: disclosed