Impact
Remote attackers can exploit unbounded resource allocation in IBM i’s host servers, debug server, Telnet, and DRDA/DDM services, resulting in denial of service. The vulnerability is categorized under CWE-770 and allows an attacker to overwhelm system resources, potentially causing service interruption and affecting availability. No evidence of credential requirements or privileged access is provided; the attack appears to be possible from any remote host able to interact with the affected services.
Affected Systems
IBM i platforms released as 7.6, 7.5, 7.4, and 7.3 are impacted. The following PTFs address each release: for 7.6 – SJ11101 (and supporting SJ11097); for 7.5 – SJ11102 (and supporting SJ11098); for 7.4 – SJ11103 (and supporting SJ11099); for 7.3 – SJ11104. All affected releases must be updated to a supported and fixed version; older Releases 7.3 and 7.4 are already unsupported.
Risk and Exploitability
The CVSS score of 7.5 signifies a high severity vulnerability, while the EPSS score is currently unavailable, making it difficult to gauge exploitation probability but not excluding it. The vulnerability is not listed in the CISA KEV catalog, but the remote nature and the possibility of causing a denial of service elevate the urgency of remediation. An attacker can reach the vulnerable services over the network; no additional attack prerequisites are described.
OpenCVE Enrichment