Executive brief
IBM i is a mission-critical operating system used by enterprises to run business applications and databases. This vulnerability allows remote attackers to bypass authentication checks in the database communication layer (DDM/DRDA), potentially gaining unauthorized access to sensitive data or manipulating business-critical database transactions without proper credentials.
Technical details
The vulnerability exists in IBM i's Distributed Data Management (DDM) / Distributed Relational Database Architecture (DRDA) layer, which handles remote database authentication and authorization. The flaw stems from improper validation of client-supplied authentication parameters, allowing a remote attacker with network access to bypass authentication controls. No user interaction or elevated privileges are required; the attack requires only network connectivity to the affected system. An attacker can gain unauthorized database access, read sensitive data, and potentially modify or delete database records. IBM has released patches (PTFs) for versions 7.3 through 7.6; affected organizations should apply the provided security updates immediately.
Affected products
- IBM i 7.3, 7.4, 7.5, 7.6
Timeline
- 2026-09-04: disclosed: Security bulletin published
- 2026-09-04: patched: PTFs available for all affected versions (7.3-7.6)