CVE-2026-18175

8.1

IBM · i

IBM i versions 7.3 through 7.6 contain an improper authorization vulnerability in the DDM target dispatcher that allows remote attackers to manipulate database transactions.

Executive summary

A high severity improper authorization vulnerability in IBM i allows remote, unauthenticated attackers to manipulate database transactions, posing a significant risk to data integrity.

Vulnerability

The vulnerability stems from improper authorization within the DDM target dispatcher component. A remote, unauthenticated attacker can exploit this flaw to perform unauthorized database operations.

Business impact

The ability for an unauthorized party to manipulate database transactions directly threatens the integrity and reliability of critical business data. Given the CVSS score of 8.1, this flaw is considered high risk, as it could lead to the corruption of financial records, theft of sensitive information, or unauthorized alteration of system configurations.

Remediation

Immediate Action: Apply the specific Program Temporary Fix (PTF) for your respective IBM i release as detailed in the IBM support documentation. Administrators must install SJ11231/SJ11230 for 7.6, SJ11232/SJ11233 for 7.5, or SJ11262/SJ11261 for 7.4.

Proactive Monitoring: Audit database transaction logs for unusual entries or unauthorized modifications that occur outside of standard application workflows. Monitor network traffic directed toward the DDM (Distributed Data Management) ports for anomalous spikes or connection patterns.

Compensating Controls: Restrict network access to the DDM target dispatcher at the firewall level to only include known, trusted IP addresses. Implementing strict network segmentation can limit the exposure of the IBM i system to external attackers.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Due to the high severity and the potential for unauthorized data manipulation, organizations running affected IBM i versions must prioritize the deployment of the provided PTF updates. Organizations should verify the integrity of their database transactions following the patch application to ensure no unauthorized changes were made prior to the update.

More IBM CVEs

Sources