Impact
The vulnerability in IBM Db2 Mirror for i arises from improper input validation that allows a remote authenticated attacker to read sensitive files or directories. This weakness is formally classified as CWE-22, which describes path traversal flaws that can be exploited to circumvent file access controls. When a valid user account is used to send malformed input, the system fails to restrict the resolution of file paths, enabling the disclosure of confidential data that should not be accessible to that user.
Affected Systems
IBM Db2 Mirror for i is affected in the 7.4, 7.5, and 7.6 releases. The IBM provided fix pack technical package numbers are SJ10947 for version 7.4, SJ10961 for 7.5, and SJ10948 for 7.6. These releases deploy on IBM i systems that host the Db2 Mirror for i component.
Risk and Exploitability
The CVSS score for this issue is 7.5, indicating a high severity. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation at the time of reporting. The likely attack vector is remote authentication; an attacker who gains valid credentials can exploit the path traversal flaw, potentially extracting files containing sensitive business or personal data.
OpenCVE Enrichment