Executive brief
IBM i is an enterprise operating system running critical business applications on AS/400 systems. A remote attacker can exploit unbounded resource allocation in the host servers to exhaust system memory or CPU, causing denial of service and disrupting business operations without authentication.
Technical details
The vulnerability is a resource exhaustion flaw (CWE-770: Allocation of Resources Without Limits or Throttling) in IBM i host servers that fails to limit resource allocation in response to client requests. An unauthenticated remote attacker can send specially crafted requests over the network to trigger unbounded allocation of memory or processing resources. This causes the affected host server process to consume excessive resources until the system becomes unresponsive, resulting in denial of service. IBM has released PTFs (SJ11101, SJ11102, SJ11103, SJ11104 for 7.6/7.5/7.4/7.3 respectively) to address this and related vulnerabilities.
Affected products
- IBM i 7.6, 7.5, 7.4, 7.3
Timeline
- 2026-08-13: disclosed