Description
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to manipulate database transactions due to improper authorization in the DDM target dispatcher.
Published: 2026-09-04
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized database transaction manipulation
Action: Immediate Patch
AI Analysis

Impact

An improper authorization flaw in the Database Definition Manager (DDM) target dispatcher lets a remote attacker craft requests that bypass normal access controls and modify database transactions. This can result in unauthorized data changes, deletions, or other integrity violations, potentially allowing an attacker to alter or destroy critical business information. The weakness maps to CWE‑285 – Improper Authorization.

Affected Systems

IBM i versions 7.3, 7.4, 7.5, and 7.6 are affected. These versions can be found as IBM i 7.3, IBM i 7.4, IBM i 7.5, and IBM i 7.6 in the vendor’s product catalog.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.1, indicating a serious impact that can be exploited remotely. The EPSS score is not available, and the flaw is not yet listed in CISA’s KEV catalog. A remote attacker with network access to the DDM service can exploit the flaw without needing valid credentials, making the risk high for environments where the DDM port is exposed to the network.

Generated by OpenCVE AI on September 4, 2026 at 18:14 UTC.

Remediation

Vendor Solution

IBM i Release5770-SS1  PTF Number(s)PTF Download Link(s)7.6SJ11231 SJ11230 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11231 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11230 7.5SJ11232 SJ11233 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11232 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11233 7.4SJ11262 SJ11261 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11262 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11261 7.3SJ11234 SJ11235 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11234 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11235 IBM recommends users running unsupported versions of affected products upgrade to a supported and fixed version of affected products.


OpenCVE Recommended Actions

  • Apply the IBM i Release5770-SS1 patches (PTFs SJ11231, SJ11230, SJ11232, SJ11233, SJ11261, SJ11262, SJ11234, SJ11235) for your specific IBM i version
  • Upgrade unsupported IBM i releases to a supported and patched version that includes the DDM fix
  • Limit network exposure by configuring firewalls or ACLs to allow DDM traffic only from trusted hosts

Generated by OpenCVE AI on September 4, 2026 at 18:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:o:ibm:i:7.6:*:*:*:*:*:*:*

Fri, 04 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to manipulate database transactions due to improper authorization in the DDM target dispatcher.
Title IBM i is Affected By Improper Authorization and Authentication Vulnerabilities in DDM / DRDA [, ]
First Time appeared Ibm
Ibm i
Weaknesses CWE-285
CPEs cpe:2.3:a:ibm:i:7.3.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm i
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-10T21:00:34.657Z

Reserved: 2026-07-28T22:12:03.066Z

Link: CVE-2026-18175

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-09-04T17:16:56.010

Modified: 2026-09-10T21:17:23.013

Link: CVE-2026-18175

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T21:15:04Z

Weaknesses