Description
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to obtain sensitive information due to external control of system configuration.
Published: 2026-08-14
Score: 8.3 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in IBM Db2 Mirror for i, where external control of system configuration is possible. This weakness allows an attacker to read sensitive information from the database via unauthorized configuration changes or manipulations. The flaw is classified as CWE‑15, meaning an attacker can influence system configuration through external inputs, compromising confidentiality. The vendor notes that the issue is limited to database versions 7.4, 7.5, and 7.6 and can be exploited remotely. The impact is the potential loss of protected data and exposure of internal configuration details to unauthorized parties.

Affected Systems

IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6 are affected. The vulnerability applies to the specified releases of the product and can affect any instance where the mirror configuration is exposed to untrusted network traffic.

Risk and Exploitability

The CVSS score of 8.3 places the vulnerability in the high‑severity range, indicating that it could have serious consequences if exploited. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog, suggesting that no widespread exploits are documented yet. However, the remote nature of the flaw means that an attacker with network access could potentially read sensitive data if the configuration interface is reachable. The vendor strongly recommends applying the PTFs immediately to mitigate the risk. The vulnerability allows remote data disclosure through improper handling of configuration inputs, so any resolution must address that pathway.

Generated by OpenCVE AI on August 14, 2026 at 20:28 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release 5770-DBM PTF Numbers PTF Download Link 7.4 SJ10947 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10947 7.5 SJ10961 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10961 7.6 SJ10948 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10948 https://www.ibm.com/support/fixcentral


OpenCVE Recommended Actions

  • Apply IBM fix pack SJ10947 to 7.4, SJ10961 to 7.5, and SJ10948 to 7.6 to correct the configuration control flaw.
  • Restrict external access to the Db2 Mirror configuration management interfaces to trusted networks or VPN connections so that only authorized personnel can modify system settings.
  • Continuously monitor audit logs for unauthorized configuration changes and enforce strict access controls and segregation of duties around database administration.

Generated by OpenCVE AI on August 14, 2026 at 20:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to obtain sensitive information due to external control of system configuration.
Title IBM Db2 Mirror for i is affected by multiple vulnerabilities
First Time appeared Ibm
Ibm db2 Mirror For I
Weaknesses CWE-15
CPEs cpe:2.3:a:ibm:db2_mirror_for_i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm db2 Mirror For I
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

Ibm Db2 Mirror For I
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-14T19:17:21.260Z

Reserved: 2026-07-23T02:00:55.012Z

Link: CVE-2026-16708

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-14T20:16:49.457

Modified: 2026-08-14T20:16:49.457

Link: CVE-2026-16708

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T22:00:04Z

Weaknesses
  • CWE-15

    External Control of System or Configuration Setting