CVE-2026-17485: IBM i is Affected By Denial of Service Vulnerability []
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and obtain sensitive information due to an integer underflow.
Other sources
IBM i could allow a remote attacker to cause a denial of service and obtain sensitive information due to an integer underflow.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM ito a version that resolves this vulnerability.Fixed in 7.6Patch MJ10909 - Upgrade
Upgrade
IBM ito a version that resolves this vulnerability.Fixed in 7.5Patch MJ10863 - Upgrade
Upgrade
IBM ito a version that resolves this vulnerability.Fixed in 7.4Patch MJ10862 - Upgrade
Upgrade
IBM ito a version that resolves this vulnerability.Fixed in 7.3Patch MJ10861
Event History
Frequently Asked Questions
Which IBM i releases are identified as affected?
IBM i 7.3, 7.4, 7.5, and 7.6 are identified as affected.
Can this be exploited remotely without authentication or user interaction?
Yes. The CVSS vector indicates network-based exploitation with low attack complexity, no privileges required, and no user interaction required.
What impact could successful exploitation have?
A remote attacker could cause a denial of service and obtain sensitive information. The stated impact includes low confidentiality impact and high availability impact.