Description
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper input validation.
Published: 2026-08-14
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in IBM Db2 Mirror for i arises from improper input validation that allows a remote authenticated attacker to read sensitive files or directories. This weakness is formally classified as CWE-22, which describes path traversal flaws that can be exploited to circumvent file access controls. When a valid user account is used to send malformed input, the system fails to restrict the resolution of file paths, enabling the disclosure of confidential data that should not be accessible to that user.

Affected Systems

IBM Db2 Mirror for i is affected in the 7.4, 7.5, and 7.6 releases. The IBM provided fix pack technical package numbers are SJ10947 for version 7.4, SJ10961 for 7.5, and SJ10948 for 7.6. These releases deploy on IBM i systems that host the Db2 Mirror for i component.

Risk and Exploitability

The CVSS score for this issue is 7.5, indicating a high severity. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation at the time of reporting. The likely attack vector is remote authentication; an attacker who gains valid credentials can exploit the path traversal flaw, potentially extracting files containing sensitive business or personal data.

Generated by OpenCVE AI on August 14, 2026 at 20:52 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release 5770-DBM PTF Numbers PTF Download Link 7.4 SJ10947 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10947 7.5 SJ10961 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10961 7.6 SJ10948 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10948 https://www.ibm.com/support/fixcentral


OpenCVE Recommended Actions

  • Apply the IBM Fix Pack PTF that addresses the vulnerability (SJ10947 for 7.4, SJ10961 for 7.5, or SJ10948 for 7.6).
  • Revoke any unnecessary privileges from user accounts that access Db2 Mirror for i and restrict authentication to the minimum required set.
  • Configure the operating system's file system permissions to prevent Db2 Mirror for i from accessing sensitive directories or files that are not part of its intended configuration.

Generated by OpenCVE AI on August 14, 2026 at 20:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper input validation.
Title IBM Db2 Mirror for i is affected by multiple vulnerabilities
First Time appeared Ibm
Ibm db2 Mirror For I
Weaknesses CWE-22
CPEs cpe:2.3:a:ibm:db2_mirror_for_i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm db2 Mirror For I
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Ibm Db2 Mirror For I
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-14T19:18:51.073Z

Reserved: 2026-07-24T06:47:11.464Z

Link: CVE-2026-16915

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-14T20:16:49.933

Modified: 2026-08-14T20:16:49.933

Link: CVE-2026-16915

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T21:00:05Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')