CVE-2026-17015: IBM i Denial of Service
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service and obtain sensitive information due to an out-of-bounds read.
Other sources
IBM i could allow a remote authenticated attacker to cause a denial of service and obtain sensitive information due to an out-of-bounds read.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM ito a version that resolves this vulnerability.Patch SJ11150 - Upgrade
Upgrade
IBM ito a version that resolves this vulnerability.Patch SJ11149 - Upgrade
Upgrade
IBM ito a version that resolves this vulnerability.Patch SJ11148 - Upgrade
Upgrade
IBM ito a version that resolves this vulnerability.Patch SJ11147
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must be remote and authenticated. The vulnerability affects IBM i versions 7.3, 7.4, 7.5, and 7.6.
What could a successful attack achieve?
A successful attacker could cause a denial of service and obtain sensitive information through an out-of-bounds read.
Does exploitation require user interaction?
No. The supplied CVSS vector indicates that no user interaction is required, but the attacker must have low-level privileges.