ZeroHour

CVE-2026-18175

mass

Unauthenticated database transaction manipulation in IBM i DDM dispatcher (CWE-285)

CVSS 3.1
7.5 high
EPSS
<1%p9
Published
()
Modified
AI analysis

CVE-2026-18175 is an improper authorization flaw (CWE-285) in the DDM target dispatcher of IBM i, the operating system that runs on IBM Power Systems. The DDM (Distributed Data Management) component handles remote database requests such as DRDA connections, and a remote, unauthenticated attacker who can reach that listener can send crafted DDM requests that bypass the dispatcher's authorization checks. The documented impact is integrity-only: the attacker can manipulate database transactions without obtaining read access to the data or disrupting availability. All four currently supported IBM i releases — 7.6, 7.5, 7.4, and 7.3 — are in scope, so essentially the entire supported IBM i installed base is affected. No proof-of-concept or in-the-wild exploitation is known; EPSS currently assigns only a 0.2% probability of exploitation within the next 30 days.

What to do: Apply IBM's corrective PTFs for the DDM target dispatcher to every IBM i 7.3, 7.4, 7.5, and 7.6 partition once IBM publishes them (check IBM Fix Central and the IBM PSIRT bulletin for this CVE). Until patched, restrict the DDM/DRDA TCP/IP server (typically ports 446 and 448) to trusted hosts and audit whether any partition's DDM listener is reachable from untrusted networks or the internet.

Affected
IBM i7.6, 7.5, 7.4, 7.3
Estimated exposure
mass≈100,000–500,000 IBM i systems (entire supported 7.3–7.6 installed base); directly internet-exposed subset likely far smaller — The IBM i installed base on IBM Power Systems is commonly estimated in the hundreds of thousands of systems and all four supported releases are affected, though most DDM/DRDA listeners sit behind firewalls, so systems whose DDM service is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to manipulate database transactions due to improper authorization in the DDM target dispatcher.

Vendors
ibm
Products
i
Weakness
CWE-285
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.