IBM InfoSphere Data Replication VSAM for z/OS Remote Source 11.4 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local user with access to the files storing CECSUB or CECRM on the container could overflow the buffer and execute arbitrary code on the system.
| Software | From | Fixed in |
|---|---|---|
| ibm / infosphere_data_replication_vsam_for_z/os_remote_source | 11.4 | 11.4.x |