Impact
The flaw in IBM Db2 Mirror for i allows a remote attacker to forge authenticated requests that are accepted by the application, letting the attacker extract sensitive data. The vulnerability is caused by improper validation of incoming requests, which permits the construction of malicious forms or calls that the server will treat as legitimate. It does not provide code execution, but the ability to read confidential information creates significant confidentiality risk.
Affected Systems
IBM Db2 Mirror for i releases 7.4, 7.5, and 7.6 on the IBM i 5770-SS1 platform are affected. The recommended fixes are the PTFs SJ11335 for 7.4, SJ11336 for 7.5, and SJ11337 for 7.6, all available through IBM Fix Central.
Risk and Exploitability
The CVSS base score of 5.4 classifies the issue as moderate severity. No EPSS data is available, so the real-world exploitation probability is unknown, but the lack of any listing in the CISA KEV catalog suggests no widely known public exploits yet. The attack likely requires the victim to be authenticated or session credentials to be present in the browser, making it a CSRF that can be triggered by a malicious user while the victim is logged in.
OpenCVE Enrichment