Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to unbounded resource allocation.
Published: 2026-08-13
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Remote attackers can exploit unbounded resource allocation in IBM i’s host servers, debug server, Telnet, and DRDA/DDM services, resulting in denial of service. The vulnerability is categorized under CWE-770 and allows an attacker to overwhelm system resources, potentially causing service interruption and affecting availability. No evidence of credential requirements or privileged access is provided; the attack appears to be possible from any remote host able to interact with the affected services.

Affected Systems

IBM i platforms released as 7.6, 7.5, 7.4, and 7.3 are impacted. The following PTFs address each release: for 7.6 – SJ11101 (and supporting SJ11097); for 7.5 – SJ11102 (and supporting SJ11098); for 7.4 – SJ11103 (and supporting SJ11099); for 7.3 – SJ11104. All affected releases must be updated to a supported and fixed version; older Releases 7.3 and 7.4 are already unsupported.

Risk and Exploitability

The CVSS score of 7.5 signifies a high severity vulnerability, while the EPSS score is currently unavailable, making it difficult to gauge exploitation probability but not excluding it. The vulnerability is not listed in the CISA KEV catalog, but the remote nature and the possibility of causing a denial of service elevate the urgency of remediation. An attacker can reach the vulnerable services over the network; no additional attack prerequisites are described.

Generated by OpenCVE AI on August 13, 2026 at 20:53 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. Host Servers IBM i Release5770-SS1 PTF Number(s)PTF Download Link(s)7.6SJ11101 SJ11097 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11101 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11097 7.5SJ11102 SJ11098 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11102 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11098 7.4SJ11103 SJ11099 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11103 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11099 7.3SJ11104 SJ11100 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11100 Debug Server IBM i Release5770-SS1 PTF Number(s)PTF Download Link(s)7.6SJ10899 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10899 Telnet IBM i Release5770-SS1 PTF Number(s)PTF Download Link(s)7.6SJ11022 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11022 DRDA/DDM IBM i Release5770-SS1 PTF Number(s)PTF Download Link(s)7.6SJ10848 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10848 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the IBM i PTFs listed (SJ11101 for 7.6, SJ11102 for 7.5, SJ11103 for 7.4, SJ11104 for 7.3) to all affected releases immediately.
  • If a particular PTF is not yet available for your system, disable the corresponding services (debug, Telnet, DRDA/DDM) or block external access to them until the update can be applied.
  • For production environments that cannot apply the PTFs at this time, implement traffic shaping or rate‑limiting on the affected ports to reduce the likelihood of resource exhaustion.
  • Ensure your IBM i system is upgraded to a supported and patched version if you are still running 7.3 or 7.4, as these releases are unsupportable and lack critical security fixes.

Generated by OpenCVE AI on August 13, 2026 at 20:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to unbounded resource allocation.
Title IBM i is Affected By Multiple Vulnerabilities in Host Servers
First Time appeared Ibm
Ibm i
Weaknesses CWE-770
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-13T19:26:09.866Z

Reserved: 2026-07-24T19:11:04.267Z

Link: CVE-2026-17199

cve-icon Vulnrichment

Updated: 2026-08-13T19:25:03.907Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-13T20:17:18.590

Modified: 2026-08-13T20:36:48.443

Link: CVE-2026-17199

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T21:00:06Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling