The CVSS 7.5 / EPSS 0.00392 gap for this IBM i heap buffer overflow isn't a signal to either over-react or dismiss—the real problem is that our measurement tools have fundamentally low fidelity for this platform. EPSS trains on exploitation data from environments with dense security tooling coverage (nmap scripts, Qualys signatures, Rapid7 instrumentation). That ecosystem never materialized at scale for IBM i, not because the platform is inherently more secure, but because market incentives never drove investment there. The 0.00392 score doesn't reliably tell you exploitation is unlikely—it tells you we lack the visibility infrastructure to know either way.
The blast radius question matters more than the exploitability question for IBM i. Unlike Windows or Linux where a heap overflow DoS typically restarts a single service, IBM i's tightly coupled architecture—decades-old green-screen applications, DB2 databases, job subsystems, and middleware all interdependent—means destabilizing QSYS.LIB components can cascade into failed batch jobs, interrupted financial processing windows, and manufacturing line failures that require manual intervention to recover. The CVSS base metrics don't capture this collateral damage surface.
There's a second, quieter risk worth accounting for: the vulnerable code path likely lives in QSYS.LIB sediment—decades-old code accumulated upon, extended, and worked around without full architectural audits. When you patch it, you're touching interfaces that may only be understood by people who've already left the organization. The patch itself is a destabilizing event the CVSS score completely misses.
Your change management timeline matters more than the EPSS score. For most platforms, the exploitation window after disclosure is days to weeks. For IBM i with quarterly fix bundles and rigid change controls, that window may stretch to months. Each quarter you defer patching adds compounding debt to an already fragile system. The question isn't whether CVSS or EPSS is right—it's whether your organization is tracking accumulated patch debt on IBM i the way it tracks it elsewhere, or whether the platform's reputation for stability has created a cognitive trap where you've implicitly agreed not to look too hard.