Description
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication.
Published: 2026-08-14
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The IBM Db2 Mirror for i 7.4, 7.5, and 7.6 contain an authentication flaw that permits a remote attacker who can authenticate to the system to retrieve sensitive information. Because the authentication mechanism does not enforce proper credential validation, the attacker can potentially read data that should be protected. This weakness is catalogued as CWE-287: Improper Authentication.

Affected Systems

Affected systems include IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6. The vulnerability was identified by IBM and mitigated with specific product fixes for each version: PTF codes SJ10947 for 7.4, SJ10961 for 7.5, and SJ10948 for 7.6.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate risk. The EPSS score is not available, and the vulnerability is not currently listed in the CISA KEV catalog. The attack vector requires an attacker to first authenticate to the system, so the exploitability is lower than an unauthenticated attack, yet it remains a serious concern for organizations that have not applied the vendor‑published patches.

Generated by OpenCVE AI on August 14, 2026 at 20:27 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release 5770-DBM PTF Numbers PTF Download Link 7.4 SJ10947 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10947 7.5 SJ10961 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10961 7.6 SJ10948 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10948 https://www.ibm.com/support/fixcentral


OpenCVE Recommended Actions

  • Apply the IBM product fix for the affected Db2 Mirror for i version using the PTF code provided in Fix Central.
  • Restrict access to the Db2 Mirror for i service, ensuring that only authorized users with appropriate privileges can authenticate.
  • Implement network segmentation or firewall rules to limit exposure of the Db2 Mirror for i service to trusted hosts until the patch is applied.

Generated by OpenCVE AI on August 14, 2026 at 20:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication.
Title IBM Db2 Mirror for i is affected by multiple vulnerabilities
First Time appeared Ibm
Ibm db2 Mirror For I
Weaknesses CWE-287
CPEs cpe:2.3:a:ibm:db2_mirror_for_i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm db2 Mirror For I
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Ibm Db2 Mirror For I
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-14T19:18:41.856Z

Reserved: 2026-07-24T06:08:29.919Z

Link: CVE-2026-16905

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-14T20:16:49.817

Modified: 2026-08-14T20:16:49.817

Link: CVE-2026-16905

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T22:00:04Z

Weaknesses