Impact
IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6 contain a path handling flaw that can allow a remote attacker to write files to arbitrary locations. This weakness, identified as CWE-22, could enable an attacker to overwrite system or application files, potentially leading to denial of service or execution of malicious code if executable files are placed in directories with execute permissions. No specific authentication bypass is mentioned, so the attacker must have network access to the affected service.
Affected Systems
The vulnerability affects IBM:Db2 Mirror for i on IBM i releases 7.4, 7.5, and 7.6. IBM has released PTFs to address the issue: SJ10947 for 7.4, SJ10961 for 7.5, and SJ10948 for 7.6, which can be downloaded from IBM support.
Risk and Exploitability
With a CVSS score of 8.2 the flaw is classified as high severity. EPSS data is not available and the issue is not listed in the CISA KEV catalog, indicating that while an exploit may exist, no publicly known exploits are documented. The likely attack vector is remote over the network to the mirror service; an attacker would exploit the path traversal flaw to write arbitrary files, potentially escalating privileges or achieving remote code execution if the written files are executable.
OpenCVE Enrichment