<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:o:ibm:i:7.3:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3oibmi7.3/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 04 Sep 2026 17:27:37 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3oibmi7.3/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authorization Bypass in IBM i DDM Target Dispatcher</title><link>https://feed.craftedsignal.io/briefs/2026-09-cve-2026-18175/</link><pubDate>Fri, 04 Sep 2026 17:27:37 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cve-2026-18175/</guid><description>A vulnerability in the IBM i DDM target dispatcher allows remote attackers to manipulate database transactions due to improper authorization handling.</description><content:encoded><![CDATA[<p>IBM i versions 7.6, 7.5, 7.4, and 7.3 contain a vulnerability identified as CVE-2026-18175 that impacts the Distributed Data Management (DDM) target dispatcher. The flaw is rooted in improper authorization checks, which can be exploited by a remote, unauthenticated attacker to manipulate database transactions. This unauthorized access could lead to the modification, corruption, or deletion of sensitive data managed by the DDM service, effectively bypassing expected access control constraints. Defenders should prioritize auditing DDM service configurations and restricting network access to the DDM target dispatcher to mitigate the risk of exploitation.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability poses a significant risk to data integrity within environments utilizing IBM i systems. If exploited, an attacker could manipulate database entries without proper credentials, potentially resulting in unauthorized data modification or corruption. Systems exposed to the public internet or untrusted network segments are at the highest risk of compromise.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Audit the use of the DDM service across the IBM i environment to determine if remote access is required.</li>
<li>Restrict access to the DDM target dispatcher port to trusted IP addresses or internal subnets via network firewalls.</li>
<li>Monitor IBM i logs for unusual transaction activity associated with DDM-connected remote sessions.</li>
<li>Apply official vendor patches or PTFs provided by IBM as soon as they become available for versions 7.6, 7.5, 7.4, and 7.3.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>database-security</category></item></channel></rss>