7.4
/ 10
HIGH
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
IBM InfoSphere Data Replication VSAM for z/OS Remote Source 11.4 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local user with access to the files storing CECSUB or CECRM on the container could overflow the buffer and execute arbitrary code on the system.
Basic Information
ID
CVE-2025-36156
Source
ibm
Published
Oct 7, 2025 at 17:36
Modified
Oct 7, 2025 at 18:26
Affected Product
Vendor
IBM
Product
InfoSphere Data Replication VSAM for z/OS Remote Source
Affected Versions
IBM InfoSphere Data Replication VSAM for z/OS Remote Source 0