Impact
IBM Db2 Mirror for i versions 7.4–7.6 contain improper validation of file paths that allows a remote authenticated attacker to read arbitrary files on the system, exposing sensitive information. The vulnerability is a path traversal flaw (CWE‑22) and does not provide code execution capability. The impact is therefore restricted to unauthorized disclosure of data rather than system compromise.
Affected Systems
IBM Db2 Mirror for i, specifically releases 7.4, 7.5, and 7.6. The affected versions are cited in the vendor’s resolution material and match the CPE strings listed for those releases.
Risk and Exploitability
The CVSS score for this issue is 6.5, indicating moderate severity. EPSS information is not available, and the vulnerability is not listed in CISA KEV. Attack requires a valid authenticated account, so the threat is limited to users with database access. Because the flaw is a classic path traversal, exploitation is straightforward for an attacker who can authenticate, and the risk is thus considered moderate to high in environments where database credentials are not tightly controlled.
OpenCVE Enrichment