Description
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to the ability to disable server-side input validation via a request parameter.
Published: 2026-08-14
Score: 6.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6 contain a flaw that lets a remote authenticated attacker disable server‑side input validation through a request parameter. By disabling this validation, the attacker can supply data that would normally be sanitized, potentially enabling unauthorized operations on the database. The vulnerability is classified as CWE‑693 and has a CVSS score of 6.3, indicating a moderate level of risk.

Affected Systems

The affected product is IBM Db2 Mirror for i. All releases of version 7.4, 7.5, and 7.6 are impacted. Specific patch (PTF) numbers are SJ10947 for 7.4, SJ10961 for 7.5, and SJ10948 for 7.6.

Risk and Exploitability

The CVSS score reflects a moderate severity, and no EPSS score is available. The vulnerability is not currently listed in the CISA KEV catalog. The likely attack vector is a remote authenticated request that manipulates the dedicated parameter to turn off validation. Exploitation requires valid credentials to access the mirror service; once the parameter is altered, the attacker can perform actions previously restricted by security controls, such as injecting disallowed data or performing privileged queries. Given the vulnerability’s moderate severity and the lack of public exploits, immediate patching is recommended to eliminate the object of exploitation.

Generated by OpenCVE AI on August 14, 2026 at 20:27 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release 5770-DBM PTF Numbers PTF Download Link 7.4 SJ10947 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10947 7.5 SJ10961 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10961 7.6 SJ10948 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10948 https://www.ibm.com/support/fixcentral


OpenCVE Recommended Actions

  • Apply the IBM patch for your release – SJ10947 for Db2 Mirror i 7.4, SJ10961 for 7.5, or SJ10948 for 7.6 – following the instructions at the IBM Fix Central page.
  • After patching, verify that the configuration does not allow disabling server‑side input validation via request parameters, and restrict any such configuration to trusted service accounts only.
  • Limit the credentials of users or services that can access the peer‑to‑peer mirror request interface, ensuring that only roles with a legitimate need can send requests that manipulate validation settings.

Generated by OpenCVE AI on August 14, 2026 at 20:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to the ability to disable server-side input validation via a request parameter.
Title IBM Db2 Mirror for i is affected by multiple vulnerabilities
First Time appeared Ibm
Ibm db2 Mirror For I
Weaknesses CWE-693
CPEs cpe:2.3:a:ibm:db2_mirror_for_i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm db2 Mirror For I
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Ibm Db2 Mirror For I
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-14T19:19:08.395Z

Reserved: 2026-07-24T14:28:27.746Z

Link: CVE-2026-17079

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-14T20:16:50.060

Modified: 2026-08-14T20:16:50.060

Link: CVE-2026-17079

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T20:30:04Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure