Impact
IBM i versions 7.6, 7.5, 7.4, and 7.3 contain an integer error that occurs when the system processes DRDA large‑object headers. An attacker who can send a malicious DRDA request may trigger this error, causing the database service to terminate or restart and resulting in a denial of service. The flaw is classified as CWE‑190, indicating an integer overflow/underflow that can disrupt normal operation.
Affected Systems
Affected products are IBM i systems running Release 7.6, 7.5, 7.4, or 7.3. These versions are identified by the cpe strings for IBM:i 7.3 through 7.6.
Risk and Exploitability
The CVSS score of 5.3 reflects a moderate severity. EPSS data is not available, and the vulnerability is not listed in CISA KEV, suggesting no known widespread exploitation, but the remote nature of the attack vector and the impact to service availability warrant monitoring. An attacker would need network access to the DRDA interface and could exploit the integer error by sending a crafted large‑object header, which may require some knowledge of the DB2/DRDA protocol. Because the error can only cause a temporary service interruption, the damage is limited to availability disruption rather than data breach.
OpenCVE Enrichment