Executive brief
IBM i is an enterprise operating system used to run mission-critical business applications. An authenticated attacker could exploit a flaw in the Portable Application Solutions Environment (PASE) component to access sensitive information about system processes they should not be permitted to view. This could expose confidential operational details and compromise system security.
Technical details
This vulnerability is an information exposure flaw (CWE-200) in IBM i's PASE component that allows an authenticated attacker with network access to retrieve sensitive process information they are not authorized to access. The issue requires an attacker to be authenticated to the system (PR:L), but does not require user interaction. No patches have been released as of the publication date; IBM has issued PTFs (Program Temporary Fixes) MJ11365, MJ11364, MJ11363, and MJ11362 for versions 7.6, 7.5, 7.4, and 7.3 respectively. The vulnerability impacts confidentiality (C:H) while integrity and availability remain unaffected.
Affected products
- IBM i 7.6 7.6
- IBM i 7.5 7.5
- IBM i 7.4 7.4
- IBM i 7.3 7.3
Timeline
- 2026-09-04: disclosed: Vulnerability disclosed by IBM