Impact
IBM i 7.6, 7.5, 7.4, and 7.3 contain a resource exhaustion flaw that allows a remote attacker to trigger a denial of service. The flaw leads to resource depletion, potentially terminating services or crashing the system. This issue is classified as CWE-400, a resource exhaustion weakness.
Affected Systems
Affected systems are IBM i releases 7.3 through 7.6, including any environment running those versions. Unsupported or unpatched variants are especially vulnerable, while newer supported releases incorporate the fix.
Risk and Exploitability
The vulnerability carries a CVSS score of 5.3 indicating moderate severity. No EPSS score is available and the issue is not listed in the CISA KEV catalog, suggesting no confirmed exploitation yet. Attackers can realistically exploit the flaw remotely, but success hinges on network exposure to the IBM i DRDA/ DDM interfaces.
OpenCVE Enrichment