CVE-2025-36156: IBM InfoSphere Data Replication Vsam For Z/os Remote Source
High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.
IBM InfoSphere Data Replication VSAM for z/OS Remote Source 11.4 is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. A local user with access to the files storing CECSUB or CECRM on the container could overflow the buffer and execute arbitrary code on the system.
Affected products
- IBM InfoSphere Data Replication Vsam For Z/os Remote Source: version 11.4 only
Published 2025-10-07. Last modified 2026-10-08.