Sceawere

Vulnerability Detail

CVE-2026-17076UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

IBM i DRDA/DDM Denial of Service

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
2h ago
Vendor
IBM
Product
i
Attack Type
CWE-770 Allocation of Resources Without Limits or Throttling
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Attack Complexity
LOW

Narrative and Response

Description

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper processing of DRDA and DDM resynchronization requests.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-08-13T21:17:41.520Z",
  "pubdate": "2026-08-13T21:17:41.520Z",
  "executiveSummary": "This vulnerability involves a denial of service flaw affecting IBM i versions 7.3, 7.4, 7.5, and 7.6. The root cause stems from improper processing of Distributed Relational Database Architecture (DRDA) and Distributed Data Management (DDM) resynchronization requests by the affected systems.\nA remote attacker can exploit this vulnerability by sending specially crafted DRDA or DDM resynchronization requests to the target system. Successful exploitation leads to a denial of service condition, disrupting availability for legitimate database and data management operations.\nThe risk implications are significant for organizations relying on continuous database availability, as the disruption can halt critical business processes. The attack capability is remote, and the exploitation mechanism relies on protocol-level malformations or specific interaction sequences within the DRDA/DDM handling routines.\nNo specific authentication or privilege requirements are explicitly detailed in the baseline description beyond network reachability to the vulnerable services. Mitigation requires applying official vendor-supplied patches or updates corresponding to the affected IBM i releases.",
  "technicalDetails": "The vulnerability resides within the subsystem responsible for parsing and handling Distributed Relational Database Architecture (DRDA) and Distributed Data Management (DDM) protocols on IBM i. Specifically, the flaw is triggered during the handling of resynchronization requests where input validation or state management fails.\nRoot Cause: The underlying parsing logic or state machine for DRDA and DDM resynchronization sequences lacks robust error handling and boundary checks. When malformed, unexpected, or maliciously crafted resynchronization payloads are received, the affected component enters an unhandled exception state, resource exhaustion loop, or abnormal termination.\nAttack Flow: A remote attacker establishes a network connection to the service listening for DRDA and DDM traffic. The attacker then transmits a sequence of crafted bytes representing a DRDA or DDM resynchronization request designed to trigger the flaw. Upon receipt, the vulnerable component attempts to process the request without adequately validating the input structure or transaction state. This improper processing forces the service or the underlying subsystem to crash, hang, or consume excessive system resources, resulting in a denial of service.\nAffected Components: DRDA and DDM protocol handlers and associated database communication daemons within IBM i 7.3, 7.4, 7.5, and 7.6. Network Exposure: The vulnerability is exploitable remotely over the network via exposed database and data management ports utilized by DRDA and DDM services. Authentication and Privileges: Standard remote network access to the listening service is sufficient to initiate the attack sequence, depending on network segmentation and service exposure configuration. Post-Exploitation Impact: The immediate impact is localized or system-wide denial of service, preventing legitimate clients from establishing database sessions or performing distributed data management tasks until manual intervention or service recovery occurs."
}
CVE-2026-17076: IBM i DRDA/DDM Denial of Service (MEDIUM Severity, CVSS: 5.3) - Sceawere