Description
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization using user-supplied input.
Published: 2026-08-14
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6 contain an improper authorization flaw that allows a remote authenticated attacker to bypass security restrictions by supplying crafted input. The vulnerability is an instance of CWE-285 (Improper Authorization) and can enable an attacker who has valid credentials to gain elevated privileges or access protected resources they should not be able to reach, potentially compromising confidentiality and integrity of data. It is not a code‑execution flaw, but it can serve as a stepping stone to further privilege escalation within the system.

Affected Systems

The affected product is IBM Db2 Mirror for i, specifically versions 7.4, 7.5, and 7.6. IBM has released fix pack technology (PTF) updates for each affected version: SJ10947 for 7.4, SJ10961 for 7.5, and SJ10948 for 7.6, available through IBM FixCentral. Administrators should ensure that the correct PTF is applied to the installed version in order to mitigate the vulnerability.

Risk and Exploitability

The CVSS score for this vulnerability is 8.8, indicating a high severity impact. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that active exploitation may not yet be observed. The attack vector requires remote authenticated access, meaning the attacker must have valid credentials to the IBM Db2 Mirror for i system. Once authenticated, the attacker can provide user‑supplied input that the system does not properly check for authorization, thereby bypassing security controls.

Generated by OpenCVE AI on August 14, 2026 at 20:27 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release 5770-DBM PTF Numbers PTF Download Link 7.4 SJ10947 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10947 7.5 SJ10961 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10961 7.6 SJ10948 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10948 https://www.ibm.com/support/fixcentral


OpenCVE Recommended Actions

  • Apply the IBM PTF (SJ10947, SJ10961, or SJ10948) corresponding to the installed Db2 Mirror for i version via IBM FixCentral to fix the authorization flaw.
  • Enforce strict role‑based access controls so that only privileged accounts can execute operations that involve user‑supplied input, thereby reducing the risk of authorization bypass.
  • Enable and review audit logging for authentication and authorization events, and monitor logs for anomalous activity that could indicate exploitation of the flaw.

Generated by OpenCVE AI on August 14, 2026 at 20:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization using user-supplied input.
Title IBM Db2 Mirror for i is affected by multiple vulnerabilities
First Time appeared Ibm
Ibm db2 Mirror For I
Weaknesses CWE-285
CPEs cpe:2.3:a:ibm:db2_mirror_for_i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm db2 Mirror For I
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Db2 Mirror For I
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-14T19:18:18.197Z

Reserved: 2026-07-24T04:46:23.943Z

Link: CVE-2026-16879

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-14T20:16:49.700

Modified: 2026-08-14T20:16:49.700

Link: CVE-2026-16879

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T20:30:04Z

Weaknesses