Impact
A remote authenticated attacker can exploit a null pointer dereference in the IBM i debug server to terminate the service, resulting in a denial of service for applications that rely on the debug server. The flaw occurs when the debug server processes a specially crafted request that forces a null reference, causing an internal failure. The impact is limited to the availability of the debug server and any dependent services, but it does not provide direct information disclosure or privilege escalation. The underlying weakness is a classic Null Pointer Dereference (CWE‑476).
Affected Systems
IBM i operating systems 7.6, 7.5, 7.4 and 7.3 are impacted. The affected product is IBM i, and the version identifiers 7.6, 7.5, 7.4 and 7.3 are explicitly named in the advisory.
Risk and Exploitability
The CVSS v3.1 score of 6.5 indicates a moderate severity. Because the exploit requires authentication on the debug server, the attack vector is remote but not unrestricted; the attacker must have legitimate credentials. EPSS is not provided, but the lack of a KEV listing suggests no known widespread exploitation yet. Nevertheless, the impact on availability can disrupt critical business processes, especially in environments that rely heavily on the debug service. The risk is therefore significant for organizations that allow remote debugging access or operate unsupported versions of IBM i.
OpenCVE Enrichment