Impact
The vulnerability in IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6 arises from improper enforcement of authentication controls (CWE‑287). A remote attacker who possesses valid credentials can exploit this flaw to bypass authentication checks and access protected data, potentially revealing sensitive information that should be guarded by proper login procedures.
Affected Systems
Affected are IBM Db2 Mirror for i 7.4, 7.5 and 7.6. IBM has issued product fix kits with PTF numbers SJ10947 for 7.4, SJ10961 for 7.5 and SJ10948 for 7.6. These patches are available through IBM's Fix Central and apply to the respective releases.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity level, while the EPSS score is not available, so precise exploitation probability cannot be quantified at this time. The vulnerability is not listed in CISA KEV, suggesting no publicly confirmed exploits yet, but the requirement for authenticated access means that compromised or weak credentials could allow an attacker to obtain confidential data. The attack vector is likely over a network connection to the Db2 Mirror service, requiring valid user credentials. Given the high severity and potential confidentiality impact, administrators should treat this as a critical remediation priority.
OpenCVE Enrichment