Impact
The IBM Db2 Mirror for i 7.4, 7.5, and 7.6 contain an authentication flaw that permits a remote attacker who can authenticate to the system to retrieve sensitive information. Because the authentication mechanism does not enforce proper credential validation, the attacker can potentially read data that should be protected. This weakness is catalogued as CWE-287: Improper Authentication.
Affected Systems
Affected systems include IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6. The vulnerability was identified by IBM and mitigated with specific product fixes for each version: PTF codes SJ10947 for 7.4, SJ10961 for 7.5, and SJ10948 for 7.6.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate risk. The EPSS score is not available, and the vulnerability is not currently listed in the CISA KEV catalog. The attack vector requires an attacker to first authenticate to the system, so the exploitability is lower than an unauthenticated attack, yet it remains a serious concern for organizations that have not applied the vendor‑published patches.
OpenCVE Enrichment