Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to resource exhaustion.
Published: 2026-08-13
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM i 7.6, 7.5, 7.4, and 7.3 contain a resource exhaustion flaw that allows a remote attacker to trigger a denial of service. The flaw leads to resource depletion, potentially terminating services or crashing the system. This issue is classified as CWE-400, a resource exhaustion weakness.

Affected Systems

Affected systems are IBM i releases 7.3 through 7.6, including any environment running those versions. Unsupported or unpatched variants are especially vulnerable, while newer supported releases incorporate the fix.

Risk and Exploitability

The vulnerability carries a CVSS score of 5.3 indicating moderate severity. No EPSS score is available and the issue is not listed in the CISA KEV catalog, suggesting no confirmed exploitation yet. Attackers can realistically exploit the flaw remotely, but success hinges on network exposure to the IBM i DRDA/ DDM interfaces.

Generated by OpenCVE AI on August 13, 2026 at 21:49 UTC.

Remediation

Vendor Solution

IBM i Release5770-SS1  PTF Number(s)PTF Download Link(s)7.6SJ10836 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10836 7.5SJ10837 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10837 7.4SJ10838 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10838 7.3SJ10839 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10839 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the IBM i Release5770-SS1 patch or install the PTFs listed for each affected version: SJ10836 for 7.6, SJ10837 for 7.5, SJ10838 for 7.4, and SJ10839 for 7.3.
  • Upgrade from unsupported versions to a supported, fixed release of IBM i.
  • If an upgrade is not immediately feasible, limit or monitor connections to the DRDA/ DDM interfaces to reduce resource usage and mitigate the denial of service risk.

Generated by OpenCVE AI on August 13, 2026 at 21:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to resource exhaustion.
Title IBM i is Affected By A Denial of Service Vulnerability in DRDA / DDM []
First Time appeared Ibm
Ibm i
Weaknesses CWE-400
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-13T20:26:05.816Z

Reserved: 2026-07-24T14:26:16.285Z

Link: CVE-2026-17078

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-13T21:17:41.780

Modified: 2026-08-13T21:17:41.780

Link: CVE-2026-17078

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T22:15:03Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption