Impact
A memory leak in the IBM i debug server can be triggered by an authenticated remote user, allowing the attacker to exhaust system resources and cause a denial of service. The vulnerability does not expose data or enable code execution, but it can interrupt business services by forcing the operating system to crash or become unresponsive. The underlying weakness is a classic memory leak (CWE-401).
Affected Systems
IBM i operating system versions 7.6, 7.5, 7.4, and 7.3 are affected. The problem resides in the debug server component of these releases, and no other IBM i versions are listed as vulnerable.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate impact, and the EPSS score is not available; therefore the likelihood of exploitation is unclear. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a remote authenticated connection to the debug server; an attacker must possess valid credentials, which aligns with the remote authenticated threat model described in the advisory. If exploited, an attacker can force the system into instability, potentially causing service disruptions for users reliant on the affected IBM i installation.
OpenCVE Enrichment