Impact
A vulnerability in IBM i 7.6, 7.5, 7.4, and 7.3 allows a remote attacker to cause a denial of service by sending input that exceeds the expected size limits. The flaw is classified as resource exhaustion, which can consume system resources and render the affected services unavailable. The impact is a loss of availability, potentially affecting all users who rely on the IBM i system for critical operations.
Affected Systems
IBM i releases 7.6, 7.5, 7.4, and 7.3. Specific PTFs to address the issue include SJ10899 for 7.6, SJ10903 for 7.5, SJ10915 for 7.4, and SJ10916 for 7.3. Users of unsupported versions are advised to upgrade to a supported and fixed release. The vulnerability affects the IBM i platform globally and is not limited to specialized configurations.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, and while the EPSS score is not available, the lack of a KEV listing suggests that no widespread exploitation has been documented yet. The likely attack vector is remote, as the description states a remote attacker can trigger the flaw. Because of the vulnerability’s nature and the availability of patches, the risk is high for systems that remain unpatched, but mitigation via PTFs or a version upgrade can effectively eliminate the problem.
OpenCVE Enrichment