Impact
The vulnerability resides in the improper handling of Distributed Relational Database Architecture (DRDA) and Distributed Data Management (DDM) resynchronization requests within IBM i versions 7.3 through 7.6. Because the system fails to validate and process these requests correctly, an attacker can trigger a denial of service condition that would interrupt normal operation and potentially require a system restart. The weakness is classified as CWE-770, which pertains to resource consumption vulnerabilities that can degrade service availability.
Affected Systems
Affected vendors and products include IBM i for versions 7.3, 7.4, 7.5, and 7.6. The specific version ranges are 7.3.0‑7.3.*, 7.4.0‑7.4.*, 7.5.0‑7.5.*, and 7.6.0‑7.6.* as identified by the Common Platform Enumeration strings. IBM recommends upgrading to a supported and fixed release to eliminate the risk.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity vulnerability. An attacker can exploit the flaw remotely, as the description states a remote attacker may cause the denial of service. EPSS data is not available, so the exploitation probability cannot be quantified from the available score. The vulnerability is not listed in CISA’s KEV catalog, indicating no confirmed exploitation in the wild has been reported publicly. However, the remote nature of the exploit and the impact on availability suggest that it should be treated with high priority by administrators running the affected IBM i versions.
OpenCVE Enrichment