Executive brief
IBM i is a business-critical operating system used to run enterprise database and transactional workloads. A remote attacker can bypass authorization controls in the Distributed Data Management (DDM) subsystem to manipulate database transactions without proper credentials, potentially leading to unauthorized data modification or deletion across critical business systems.
Technical details
This vulnerability is an improper authorization flaw (CWE-285) in the DDM target dispatcher component of IBM i. An unauthenticated remote attacker on the network can exploit this by sending specially crafted DDM/DRDA protocol requests to manipulate database transactions, bypassing the authorization checks that normally protect database integrity. No user interaction or authentication is required; exploitation is network-accessible with high complexity. A successful exploit allows an attacker to modify or delete data within protected database transactions. IBM has released PTF (Program Temporary Fix) updates for versions 7.3, 7.4, 7.5, and 7.6.
Affected products
- IBM i 7.3, 7.4, 7.5, 7.6
Timeline
- 2026-09-04: disclosed
- 2026-09-04: patched: PTFs available: 7.6 (SJ11231, SJ11230), 7.5 (SJ11232, SJ11233), 7.4 (SJ11262, SJ11261), 7.3 (SJ11234, SJ11235)