Impact
A buffer overflow flaw exists in several IBM i host server components, caused by insufficient validation of client data. When a remote client sends specially crafted requests, the affected services can be forced to crash, resulting in a denial-of-service for that server. The vulnerability does not allow code execution or data exfiltration; it is limited to disrupting availability.
Affected Systems
IBM i Release 7.3, 7.4, 7.5 and 7.6 are affected. Specific components include the Host Server, Debug Server, Telnet, and DRDA/DDM services. Each release has corresponding IBM i PTFs such as SJ11101, SJ11097, SJ11102, SJ11098, SJ11103, SJ11099, SJ11104, SJ11100 for Host Server; SJ10899 for Debug Server; SJ11022 for Telnet; and SJ10848 for DRDA/DDM, which provide the necessary fixes.
Risk and Exploitability
The CVSS score of 7.5 indicates a moderate to high severity, reflecting the potential for significant interruption of business operations. No EPSS score is currently published, so the exact likelihood of exploitation is unclear; however, the lack of a listing in CISA’s KEV catalog suggests that no widespread, actively exploited instances have been reported publicly. Attackers would require network connectivity to the vulnerable services and the ability to send malformed requests, making a remote attack the most plausible vector. Given the impact on service availability, the risk remains substantial for organizations running the affected IBM i releases.
OpenCVE Enrichment