Executive brief
IBM i is an enterprise operating system that runs mission-critical business applications. A flaw in how Java handles memory pointers allows an authenticated attacker to gain elevated system privileges, potentially compromising the entire system. This could enable unauthorized access to sensitive data, modification of business systems, or system takeover.
Technical details
The vulnerability is a privilege escalation flaw (CWE-269) affecting IBM i versions 7.3–7.6. The root cause is improper validation of pointers read from Java-controlled memory addresses in the IBM Java SDK/Runtime. An authenticated remote attacker can craft a malicious Java application that exploits this pointer validation weakness to escalate privileges. The attack requires network access and valid authentication credentials, but no user interaction is necessary. IBM has released PTF (Program Temporary Fix) patches for all supported versions; patch availability is confirmed via IBM support portal.
Affected products
- IBM i 7.3, 7.4, 7.5, 7.6
Timeline
- 2026-08-12: disclosed: IBM Security Bulletin published
- 2026-08: patched: PTF patches available for versions 7.3–7.6