Impact
The vulnerability resides in IBM Db2 Mirror for i, where external control of system configuration is possible. This weakness allows an attacker to read sensitive information from the database via unauthorized configuration changes or manipulations. The flaw is classified as CWE‑15, meaning an attacker can influence system configuration through external inputs, compromising confidentiality. The vendor notes that the issue is limited to database versions 7.4, 7.5, and 7.6 and can be exploited remotely. The impact is the potential loss of protected data and exposure of internal configuration details to unauthorized parties.
Affected Systems
IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6 are affected. The vulnerability applies to the specified releases of the product and can affect any instance where the mirror configuration is exposed to untrusted network traffic.
Risk and Exploitability
The CVSS score of 8.3 places the vulnerability in the high‑severity range, indicating that it could have serious consequences if exploited. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog, suggesting that no widespread exploits are documented yet. However, the remote nature of the flaw means that an attacker with network access could potentially read sensitive data if the configuration interface is reachable. The vendor strongly recommends applying the PTFs immediately to mitigate the risk. The vulnerability allows remote data disclosure through improper handling of configuration inputs, so any resolution must address that pathway.
OpenCVE Enrichment