Impact
An improperly validated input in IBM Reliable Scalable Cluster Technology version 3.0 allows an attacker who can send a specially crafted request to trigger a denial of service. The flaw is driven by a capacity‑exceeded weakness (CWE‑770) that prevents the system from properly limiting or sanitizing the request size or structure, resulting in resource exhaustion and availability loss.
Affected Systems
IBM Reliable Scalable Cluster Technology 3.0 running on IBM AIX versions 7.3 (TL04SP2, TL03SP3, TL02SP5) and 7.2 (TL05SP13) as well as PowerVM VIOS Levels 4.1.2 (4.1.2.20), 4.1.1 (4.1.1.30), and 4.1.0 (4.1.0.50). The vulnerability is specific to the RSCT product and not reported for other IBM software.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.5, indicating moderate severity. An EPSS score is currently unavailable, and the issue is not listed in CISA’s KEV catalog, meaning there is no confirmed widespread exploitation yet. However, the remote attack vector—involving a crafted request—implies that anyone able to reach the RSCT service could potentially trigger the denial of service. Without timely patching, affected clusters remain at risk of unplanned downtime.
OpenCVE Enrichment