Sceawere

Vulnerability Detail

CVE-2026-17649UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

IBM i Out-of-Bounds Read Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
2h ago
Vendor
IBM
Product
i
Attack Type
CWE-125 Out-of-bounds Read
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-08-13T21:17:43.803Z",
  "pubdate": "2026-08-13T21:17:43.803Z",
  "executiveSummary": "An out-of-bounds read vulnerability has been identified in IBM i versions 7.6, 7.5, 7.4, and 7.3.\nThis security flaw allows a remote attacker to obtain sensitive information from the underlying memory space of the affected system.\nThe vulnerability arises from improper handling of boundary checks within vulnerable components, leading to unauthorized data disclosure when processing specially crafted requests.\nThe primary impact of successful exploitation is the leakage of confidential information, which may include memory contents, system configurations, or other sensitive data structures that could facilitate further attacks.\nThe risk implication is moderate to high depending on the nature of the leaked data and the exposure of the affected service.\nAttack capabilities are constrained to information disclosure; however, remote exploitation requires network connectivity to the vulnerable service without necessarily demanding prior authentication, depending on the specific attack vector exposed by the out-of-bounds condition.\nOrganizations operating the specified IBM i versions must evaluate their exposure and apply appropriate vendor-supplied fixes or configuration workarounds to mitigate the risk of unauthorized data access.",
  "technicalDetails": "The vulnerability is classified as an out-of-bounds read, stemming from a failure in the affected software components of IBM i versions 7.6, 7.5, 7.4, and 7.3 to adequately validate input lengths and memory boundaries.\nWhen the vulnerable component processes incoming data streams or requests, it fails to verify that the specified offset or read length falls within the allocated buffer boundaries.\nAs a result, a remote attacker can transmit a maliciously crafted packet or request containing manipulated parameters that direct the parsing engine to read memory addresses located outside the legitimate buffer allocation.\nThe root cause is rooted in unsafe memory access operations where bounds checking is either omitted or implemented incorrectly.\nDuring exploitation, the remote attacker initiates a connection to the exposed network service hosting the vulnerable component and supplies the malformed payload.\nThe application processes the input and performs the out-of-bounds read operation, subsequently capturing adjacent memory contents.\nDepending on how the application handles the retrieved data, the leaked memory contents may be returned to the attacker within the response payload or logged in a manner accessible to unauthorized users.\nThe attack vector is network-based, meaning the vulnerability can be triggered remotely without physical access to the host.\nThe post-exploitation impact is strictly centered around information disclosure, where the exposed memory contents could potentially expose internal application logic, session identifiers, cryptographic material, or other sensitive runtime data that aids in mapping the internal architecture or planning subsequent compromise vectors."
}
CVE-2026-17649: IBM i Out-of-Bounds Read Vulnerability (MEDIUM Severity, CVSS: 5.3) - Sceawere