PT-2025-41140 · Ibm · Ibm Infosphere Data Replication Vsam For Z/Os

Published

2025-10-06

·

Updated

2025-10-16

·

CVE-2025-36156

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM InfoSphere Data Replication VSAM for z/OS Remote Source version 11.4
Description The software contains a stack-based buffer overflow due to improper bounds checking. A local user with access to files storing CECSUB or CECRM on the container could overflow the buffer and execute arbitrary code on the system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-16253
CVE-2025-36156

Affected Products

Ibm Infosphere Data Replication Vsam For Z/Os