Impact
The vulnerability stems from an uninitialized variable used within the DRDA/DDM components of IBM i. A remote attacker who can send crafted requests to the affected service can force the system to crash or become unresponsive, resulting in a loss of availability for applications relying on the database connectivity services. The flaw is a classic example of improper initialization that falls under CWE-457 and leads to a denial‑of‑service impact rather than compromising confidentiality or integrity.
Affected Systems
IBM i versions 7.6, 7.5, 7.4, and 7.3 are affected. These releases contain the vulnerable DRDA/DDM components that can be triggered by a remote actor. The problem is present in all these four major releases of the IBM i platform.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity and the EPSS score is not available, which means that the exploitation probability is unknown at this time. Because the exploit can be performed remotely by sending crafted requests to the DRDA/DDM service, the risk to availability is real. The vulnerability is not listed in the CISA KEV catalog, but an attacker could still schedule a DoS by triggering the uninitialized variable, potentially leading to service interruptions for the affected IBM i system.
OpenCVE Enrichment