Impact
IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6 contain a flaw that lets a remote authenticated attacker disable server‑side input validation through a request parameter. By disabling this validation, the attacker can supply data that would normally be sanitized, potentially enabling unauthorized operations on the database. The vulnerability is classified as CWE‑693 and has a CVSS score of 6.3, indicating a moderate level of risk.
Affected Systems
The affected product is IBM Db2 Mirror for i. All releases of version 7.4, 7.5, and 7.6 are impacted. Specific patch (PTF) numbers are SJ10947 for 7.4, SJ10961 for 7.5, and SJ10948 for 7.6.
Risk and Exploitability
The CVSS score reflects a moderate severity, and no EPSS score is available. The vulnerability is not currently listed in the CISA KEV catalog. The likely attack vector is a remote authenticated request that manipulates the dedicated parameter to turn off validation. Exploitation requires valid credentials to access the mirror service; once the parameter is altered, the attacker can perform actions previously restricted by security controls, such as injecting disallowed data or performing privileged queries. Given the vulnerability’s moderate severity and the lack of public exploits, immediate patching is recommended to eliminate the object of exploitation.
OpenCVE Enrichment