Description
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of file paths.
Published: 2026-08-14
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM Db2 Mirror for i versions 7.4–7.6 contain improper validation of file paths that allows a remote authenticated attacker to read arbitrary files on the system, exposing sensitive information. The vulnerability is a path traversal flaw (CWE‑22) and does not provide code execution capability. The impact is therefore restricted to unauthorized disclosure of data rather than system compromise.

Affected Systems

IBM Db2 Mirror for i, specifically releases 7.4, 7.5, and 7.6. The affected versions are cited in the vendor’s resolution material and match the CPE strings listed for those releases.

Risk and Exploitability

The CVSS score for this issue is 6.5, indicating moderate severity. EPSS information is not available, and the vulnerability is not listed in CISA KEV. Attack requires a valid authenticated account, so the threat is limited to users with database access. Because the flaw is a classic path traversal, exploitation is straightforward for an attacker who can authenticate, and the risk is thus considered moderate to high in environments where database credentials are not tightly controlled.

Generated by OpenCVE AI on August 14, 2026 at 20:26 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release 5770-DBM PTF Numbers PTF Download Link 7.4 SJ10947 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10947 7.5 SJ10961 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10961 7.6 SJ10948 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10948 https://www.ibm.com/support/fixcentral


OpenCVE Recommended Actions

  • Download and apply the IBM i Release PTF that corresponds to your Db2 Mirror for i version (SJ10947 for 7.4, SJ10961 for 7.5, or SJ10948 for 7.6) using IBM Fix Central.
  • Reboot the IBM i system and restart the Db2 Mirror for i service to activate the patch fully.
  • Monitor system logs for unauthorized file read attempts and treat any suspicious activity as a potential exploitation until the patch is fully validated.

Generated by OpenCVE AI on August 14, 2026 at 20:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of file paths.
Title IBM Db2 Mirror for i is affected by multiple vulnerabilities
First Time appeared Ibm
Ibm db2 Mirror For I
Weaknesses CWE-22
CPEs cpe:2.3:a:ibm:db2_mirror_for_i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm db2 Mirror For I
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Ibm Db2 Mirror For I
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-14T19:19:45.402Z

Reserved: 2026-07-24T18:15:55.690Z

Link: CVE-2026-17173

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-14T20:16:50.307

Modified: 2026-08-14T20:16:50.307

Link: CVE-2026-17173

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T21:30:04Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')