Impact
IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6 contain an improper authorization flaw that allows a remote authenticated attacker to bypass security restrictions by supplying crafted input. The vulnerability is an instance of CWE-285 (Improper Authorization) and can enable an attacker who has valid credentials to gain elevated privileges or access protected resources they should not be able to reach, potentially compromising confidentiality and integrity of data. It is not a code‑execution flaw, but it can serve as a stepping stone to further privilege escalation within the system.
Affected Systems
The affected product is IBM Db2 Mirror for i, specifically versions 7.4, 7.5, and 7.6. IBM has released fix pack technology (PTF) updates for each affected version: SJ10947 for 7.4, SJ10961 for 7.5, and SJ10948 for 7.6, available through IBM FixCentral. Administrators should ensure that the correct PTF is applied to the installed version in order to mitigate the vulnerability.
Risk and Exploitability
The CVSS score for this vulnerability is 8.8, indicating a high severity impact. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that active exploitation may not yet be observed. The attack vector requires remote authenticated access, meaning the attacker must have valid credentials to the IBM Db2 Mirror for i system. Once authenticated, the attacker can provide user‑supplied input that the system does not properly check for authorization, thereby bypassing security controls.
OpenCVE Enrichment