Impact
IBM Db2 Mirror for i suffers an out‑of‑bounds read that allows a remote attacker to cause a denial of service by triggering a crash of the mirroring service, thereby interrupting database replication.
Affected Systems
IBM Db2 Mirror for i released as 7.4, 7.5 and 7.6 on IBM i systems are affected; the vulnerability is present in all three major versions and is mitigated by their respective IBM i Release point fixes.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. The description states that a remote attacker can trigger the defect, implying a network‑based attack vector using the mirroring interface; exploitation would result in service interruption without compromising data confidentiality or integrity.
OpenCVE Enrichment