Description
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write arbitrary files due to improper limitation of a pathname to a restricted directory.
Published: 2026-08-14
Score: 8.2 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6 contain a path handling flaw that can allow a remote attacker to write files to arbitrary locations. This weakness, identified as CWE-22, could enable an attacker to overwrite system or application files, potentially leading to denial of service or execution of malicious code if executable files are placed in directories with execute permissions. No specific authentication bypass is mentioned, so the attacker must have network access to the affected service.

Affected Systems

The vulnerability affects IBM:Db2 Mirror for i on IBM i releases 7.4, 7.5, and 7.6. IBM has released PTFs to address the issue: SJ10947 for 7.4, SJ10961 for 7.5, and SJ10948 for 7.6, which can be downloaded from IBM support.

Risk and Exploitability

With a CVSS score of 8.2 the flaw is classified as high severity. EPSS data is not available and the issue is not listed in the CISA KEV catalog, indicating that while an exploit may exist, no publicly known exploits are documented. The likely attack vector is remote over the network to the mirror service; an attacker would exploit the path traversal flaw to write arbitrary files, potentially escalating privileges or achieving remote code execution if the written files are executable.

Generated by OpenCVE AI on August 14, 2026 at 20:26 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release 5770-DBM PTF Numbers PTF Download Link 7.4 SJ10947 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10947 7.5 SJ10961 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10961 7.6 SJ10948 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10948 https://www.ibm.com/support/fixcentral


OpenCVE Recommended Actions

  • Apply the IBM-provided PTFs (SJ10947 for 7.4, SJ10961 for 7.5, SJ10948 for 7.6) obtained from IBM support.
  • Restrict network access to the Db2 Mirror service to trusted hosts or subnet ranges to limit exposure to the flaw.
  • Enable or review logging of file creation and modification events to detect suspicious activity related to arbitrary file writes.

Generated by OpenCVE AI on August 14, 2026 at 20:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write arbitrary files due to improper limitation of a pathname to a restricted directory.
Title IBM Db2 Mirror for i is affected by multiple vulnerabilities
First Time appeared Ibm
Ibm db2 Mirror For I
Weaknesses CWE-22
CPEs cpe:2.3:a:ibm:db2_mirror_for_i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm db2 Mirror For I
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L'}


Subscriptions

Ibm Db2 Mirror For I
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-14T19:19:25.532Z

Reserved: 2026-07-24T14:30:33.243Z

Link: CVE-2026-17081

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-14T20:16:50.180

Modified: 2026-08-14T20:16:50.180

Link: CVE-2026-17081

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T20:30:04Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')