Impact
An improper authorization flaw in the Database Definition Manager (DDM) target dispatcher lets a remote attacker craft requests that bypass normal access controls and modify database transactions. This can result in unauthorized data changes, deletions, or other integrity violations, potentially allowing an attacker to alter or destroy critical business information. The weakness maps to CWE‑285 – Improper Authorization.
Affected Systems
IBM i versions 7.3, 7.4, 7.5, and 7.6 are affected. These versions can be found as IBM i 7.3, IBM i 7.4, IBM i 7.5, and IBM i 7.6 in the vendor’s product catalog.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.1, indicating a serious impact that can be exploited remotely. The EPSS score is not available, and the flaw is not yet listed in CISA’s KEV catalog. A remote attacker with network access to the DDM service can exploit the flaw without needing valid credentials, making the risk high for environments where the DDM port is exposed to the network.
OpenCVE Enrichment