Executive brief
IBM i is a server operating system used by enterprise organizations for business-critical applications. A vulnerability in its Java Secure Sockets Extension (JSSE) component allows authenticated remote attackers to read sensitive data from the system due to confusion between byte counts and element counts in protocol handling. This could expose confidential business information transmitted over TLS connections.
Technical details
The vulnerability is an information disclosure flaw (CWE-200) in IBM i's Java Secure Sockets Extension, affecting versions 7.3 through 7.6. It stems from a byte-count and element-count confusion that allows a remote, authenticated attacker without special privileges to obtain sensitive information over the network. The vulnerability requires an existing authenticated connection (PR:L) but no user interaction. An attacker can leverage this to read confidential data during TLS session handling. IBM has released security patches (PTFs) for all affected versions.
Affected products
- IBM i 7.3, 7.4, 7.5, 7.6
Timeline
- 2026-08-13: disclosed
- 2026-08-13: patched: PTFs released for all affected versions