Description
IBM Reliable Scalable Cluster Technology (RSCT) 3.0 could allow a remote attacker to cause a denial of service by sending a specially crafted request due improper input validation.
Published: 2026-08-19
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improperly validated input in IBM Reliable Scalable Cluster Technology version 3.0 allows an attacker who can send a specially crafted request to trigger a denial of service. The flaw is driven by a capacity‑exceeded weakness (CWE‑770) that prevents the system from properly limiting or sanitizing the request size or structure, resulting in resource exhaustion and availability loss.

Affected Systems

IBM Reliable Scalable Cluster Technology 3.0 running on IBM AIX versions 7.3 (TL04SP2, TL03SP3, TL02SP5) and 7.2 (TL05SP13) as well as PowerVM VIOS Levels 4.1.2 (4.1.2.20), 4.1.1 (4.1.1.30), and 4.1.0 (4.1.0.50). The vulnerability is specific to the RSCT product and not reported for other IBM software.

Risk and Exploitability

The vulnerability carries a CVSS score of 6.5, indicating moderate severity. An EPSS score is currently unavailable, and the issue is not listed in CISA’s KEV catalog, meaning there is no confirmed widespread exploitation yet. However, the remote attack vector—involving a crafted request—implies that anyone able to reach the RSCT service could potentially trigger the denial of service. Without timely patching, affected clusters remain at risk of unplanned downtime.

Generated by OpenCVE AI on August 20, 2026 at 08:56 UTC.

Remediation

Vendor Solution

A.  APARS IBM has assigned the following APAR to this problem:  APARAvailability  IJ5899008/14/2026 B.  FIXES IBM strongly recommends addressing the vulnerability now.  AIX and VIOS levels including the fix for RSCT vulnerability are available and can be downloaded from Fix Central: https://www.ibm.com/support/fixcentral AIX Level Service PackAIX 7.3 TL04SP2AIX 7.3 TL03SP3AIX 7.3 TL02SP5AIX 7.2 TL05 SP13 PowerVM VIOS LevelFix PackVIOS 4.1.2 4.1.2.20VIOS 4.1.1 4.1.1.30VIOS 4.1.0  4.1.0.50


OpenCVE Recommended Actions

  • Apply the IBM APAR IJ5899008/14/2026 to address the RSCT input validation flaw
  • Install the corresponding AIX or VIOS security fix pack matching the appliance’s version (for example, AIX 7.3 TL04SP2 or VIOS 4.1.2.20) via Fix Central
  • Plan and execute a maintenance window to apply the fix, ensuring minimal disruption to cluster operations

Generated by OpenCVE AI on August 20, 2026 at 08:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ibm:reliable_scalable_cluster_technology:3.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:reliable_scalable_cluster_technology:3.3:*:*:*:*:*:*:*

Thu, 20 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description IBM Reliable Scalable Cluster Technology (RSCT) 3.0 could allow a remote attacker to cause a denial of service by sending a specially crafted request due improper input validation.
Title Reliable Scalable Cluster Technology Denial-of-Service
First Time appeared Ibm
Ibm reliable Scalable Cluster Technology
Weaknesses CWE-770
CPEs cpe:2.3:a:ibm:reliable_scalable_cluster_technology:3.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm reliable Scalable Cluster Technology
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Ibm Reliable Scalable Cluster Technology
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-20T14:07:31.122Z

Reserved: 2026-07-02T19:22:30.389Z

Link: CVE-2026-14514

cve-icon Vulnrichment

Updated: 2026-08-20T14:07:24.508Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T21:16:53.883

Modified: 2026-09-04T17:05:14.773

Link: CVE-2026-14514

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T09:00:05Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling