Sceawere

Vulnerability Detail

CVE-2026-17199UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

IBM i Denial of Service

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
3h ago
Vendor
IBM
Product
i
Attack Type
CWE-770 Allocation of Resources Without Limits or Throttling
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to unbounded resource allocation.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-08-13T20:17:18.590Z",
  "pubdate": "2026-08-13T20:17:18.590Z",
  "executiveSummary": "A denial of service vulnerability exists within IBM i versions 7.6, 7.5, 7.4, and 7.3 that could allow a remote attacker to cause a denial of service due to unbounded resource allocation.\nThis vulnerability manifests as an improper resource management flaw, specifically unbounded resource allocation, which can be triggered remotely by an unauthenticated or authenticated attacker depending on the specific network service exposed.\nSuccessful exploitation of this flaw enables a malicious actor to exhaust critical system resources such as memory, CPU, or connection pools, leading to service degradation, application crashes, or complete system unresponsiveness.\nThe risk implications are severe for environments relying on continuous availability of the affected operating systems, as operational disruption can impact mission-critical workloads.\nMitigation requires applying official vendor-supplied fixes or temporary workarounds as provided by IBM to restrict resource consumption and prevent exhaustion attacks.",
  "technicalDetails": "The vulnerability is rooted in an unbounded resource allocation flaw present in IBM i 7.6, 7.5, 7.4, and 7.3.\nThe affected component fails to adequately limit, throttle, or release system resources allocated during incoming request processing or network communication sessions.\nAn attacker initiates exploitation by sending a specially crafted sequence of network requests or data payloads to a vulnerable service running on the target IBM i system.\nBecause the application logic does not enforce strict quotas or threshold limits on resource consumption per session or connection, the targeted component continues to allocate memory, process threads, or file descriptors indefinitely or until system thresholds are saturated.\nThe attack flow typically involves the adversary establishing network connections and repeatedly triggering resource-intensive operations without properly terminating the session or releasing the acquired handles.\nAs resource allocation scales unboundedly, the underlying operating system experiences severe resource starvation.\nThis leads to secondary failures such as out-of-memory conditions, thread exhaustion, or CPU pinning, ultimately resulting in a denial of service condition for legitimate users and services.\nThe vulnerability is remotely exploitable over the network, and the exact privilege and authentication requirements depend on the specific network daemon or subsystem exhibiting the unbounded allocation behavior."
}
CVE-2026-17199: IBM i Denial of Service (HIGH Severity, CVSS: 7.5) - Sceawere