Description
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication enforcement.
Published: 2026-08-14
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6 arises from improper enforcement of authentication controls (CWE‑287). A remote attacker who possesses valid credentials can exploit this flaw to bypass authentication checks and access protected data, potentially revealing sensitive information that should be guarded by proper login procedures.

Affected Systems

Affected are IBM Db2 Mirror for i 7.4, 7.5 and 7.6. IBM has issued product fix kits with PTF numbers SJ10947 for 7.4, SJ10961 for 7.5 and SJ10948 for 7.6. These patches are available through IBM's Fix Central and apply to the respective releases.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity level, while the EPSS score is not available, so precise exploitation probability cannot be quantified at this time. The vulnerability is not listed in CISA KEV, suggesting no publicly confirmed exploits yet, but the requirement for authenticated access means that compromised or weak credentials could allow an attacker to obtain confidential data. The attack vector is likely over a network connection to the Db2 Mirror service, requiring valid user credentials. Given the high severity and potential confidentiality impact, administrators should treat this as a critical remediation priority.

Generated by OpenCVE AI on August 14, 2026 at 20:26 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release 5770-DBM PTF Numbers PTF Download Link 7.4 SJ10947 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10947 7.5 SJ10961 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10961 7.6 SJ10948 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10948 https://www.ibm.com/support/fixcentral


OpenCVE Recommended Actions

  • Install the IBM PTF patch (SJ10947 for 7.4, SJ10961 for 7.5, or SJ10948 for 7.6) from IBM Fix Central to correct the authentication enforcement flaw.
  • Verify that authentication checks are enabled and that only authorized users can access the Db2 Mirror for i instances.
  • Reduce the exposure of the Db2 Mirror service by restricting remote connections via firewall rules or using secure VPN tunnels.

Generated by OpenCVE AI on August 14, 2026 at 20:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication enforcement.
Title IBM Db2 Mirror for i is affected by multiple vulnerabilities
First Time appeared Ibm
Ibm db2 Mirror For I
Weaknesses CWE-287
CPEs cpe:2.3:a:ibm:db2_mirror_for_i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm db2 Mirror For I
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Ibm Db2 Mirror For I
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-14T19:20:16.629Z

Reserved: 2026-07-24T18:23:01.767Z

Link: CVE-2026-17175

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-14T20:16:50.430

Modified: 2026-08-14T20:16:50.430

Link: CVE-2026-17175

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T20:30:04Z

Weaknesses