Impact
The vulnerability arises when IBM i DDM/DRDA improperly validates client‑supplied authentication parameters, allowing a remote attacker to authenticate without proper credentials and potentially gain full system access. This flaw is an instance of Improper Authentication (CWE‑287).
Affected Systems
IBM i versions 7.6, 7.5, 7.4, and 7.3 are affected. The flaw impacts the DDM/DRDA interfaces. PTFs such as SJ11230, SJ11231, SJ11232, SJ11233, SJ11234, SJ11235, SJ11261, and SJ11262 address the vulnerability for the corresponding release levels.
Risk and Exploitability
The CVSS score is 8.1, indicating high severity. EPSS is not available, and the vulnerability is not listed in CISA KEV, so no known exploitation in the wild has been reported. The attack vector is remote and network‑based, as the flaw exists in a protocol exposed by DDM/DRDA. An attacker must supply crafted authentication parameters, suggesting that connections from untrusted networks could be exploited if no mitigation is applied.
OpenCVE Enrichment