Sceawere

Vulnerability Detail

CVE-2026-17078UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

IBM i Denial of Service Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
2h ago
Vendor
IBM
Product
i
Attack Type
CWE-400 Uncontrolled Resource Consumption
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Attack Complexity
LOW

Narrative and Response

Description

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to resource exhaustion.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-08-13T21:17:41.780Z",
  "pubdate": "2026-08-13T21:17:41.780Z",
  "executiveSummary": "A denial of service vulnerability exists within IBM i versions 7.3, 7.4, 7.5, and 7.6 that can be leveraged by a remote adversary to induce resource exhaustion on target systems.\nThe vulnerability directly impacts system availability by overwhelming critical processing or memory resources, preventing legitimate users and processes from accessing system services.\nThis security flaw enables remote attackers with network access to execute disruptive operations without requiring prior authentication or elevated privileges, depending on the specific attack vector.\nSuccessful exploitation results in service degradation or complete system unresponsiveness, necessitating administrative intervention to restore normal operations.\nGiven the remote attack vector and potential for system-wide availability disruption, organizations utilizing the affected IBM i releases face significant operational risks if defensive measures are not applied.",
  "technicalDetails": "The vulnerability stems from improper resource management within IBM i 7.3, 7.4, 7.5, and 7.6, which allows unauthenticated remote actors to trigger excessive consumption of system resources.\nWhen exposed network services or internal components process maliciously crafted requests or an inundation of traffic, they fail to adequately bound memory, CPU cycles, or thread allocations.\nThe exploitation method involves an attacker transmitting specially crafted network payloads directly to the vulnerable component, bypassing authentication mechanisms where applicable.\nUpon receipt of the malicious payload, the affected software or underlying subsystem enters an iterative or blocking state that continuously consumes finite system resources without releasing them.\nThe attack flow proceeds as follows: first, the remote adversary establishes network connectivity with the target IBM i system; second, the attacker transmits the resource-exhaustion payload; third, the vulnerable component attempts to process the request, leading to unbounded resource allocation; fourth, system limits are reached, resulting in a denial of service condition.\nThe technical impact includes CPU saturation, memory depletion, or thread exhaustion across the affected IBM i operating system environment.\nNo specific privileges or authentication prerequisites are mandated by the fundamental flaw, enabling remote exploitation across network boundaries against IBM i 7.3, 7.4, 7.5, and 7.6 deployments."
}
CVE-2026-17078: IBM i Denial of Service Vulnerability (MEDIUM Severity, CVSS: 5.3) - Sceawere