Impact
The flaw in IBM Db2 Mirror for i arises from a lack of proper neutralization of special characters within an OS command, allowing an attacker who can send specially crafted input to the service to execute arbitrary commands on the host system. This provides a pathway for full remote code execution, jeopardizing confidentiality, integrity, and availability of the affected database and the underlying operating system. The weakness is classified as CWE‑78, attributable to insecure command construction.
Affected Systems
IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6 are affected. The specific patches that address this issue are PTF SJ10957 (IBM i Release 7.4), SJ10954 (IBM i Release 7.5), and SJ10951 (IBM i Release 7.6), available through IBM’s support links.
Risk and Exploitability
With a CVSS score of 9.8 the vulnerability is considered critical. An exploitation is possible by a remote attacker who can interact with the vulnerable component; the attack likely involves sending a crafted request that causes the vulnerable process to invoke an OS command containing unsanitized user input. The EPSS score is 1%, indicating a low but nonzero exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog at this time. Nonetheless the high severity and remote nature mean the risk remains significant until the relevant patches are applied.
OpenCVE Enrichment