Description
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service due to uncontrolled recursion.
Published: 2026-08-14
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an uncontrolled recursion that can cause IBM Db2 Mirror for i to crash, resulting in a denial of service. The flaw is classified as CWE-674 and enables a remote attacker to trigger the recursion, making the database unavailable for legitimate users.

Affected Systems

IBM Db2 Mirror for i version 7.4, 7.5, and 7.6 on IBM i systems are affected. These releases are identified by the PTFs SJ10947 (7.4), SJ10961 (7.5), and SJ10948 (7.6). The vulnerability impacts all instances running these releases.

Risk and Exploitability

The CVSS score of 7.5 indicates high severity. The description states that a remote attacker can trigger the uncontrolled recursion, implying that the attack surface is the network and that it does not require local privileges. Because the EPSS score is not available, the likelihood of exploitation in the wild cannot be quantified, but the nature of the bug suggests that exploitation is straightforward. The vulnerability is not listed in the CISA KEV catalog, so there are no known large-scale incidents recorded, but the absence of exploitation data does not mitigate the risk. Immediate patching is advised to avoid potential denial of service outages.

Generated by OpenCVE AI on August 14, 2026 at 20:52 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release 5770-DBM PTF Numbers PTF Download Link 7.4 SJ10947 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10947 7.5 SJ10961 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10961 7.6 SJ10948 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10948 https://www.ibm.com/support/fixcentral


OpenCVE Recommended Actions

  • Download and install the IBM Db2 Mirror for i Product Fixes: PTF SJ10947 for 7.4, PTF SJ10961 for 7.5, and PTF SJ10948 for 7.6 from IBM Fix Central.
  • Restart the Db2 Mirror for i service to apply the patch.
  • As a temporary measure, restrict external network access to the database instance until the patch is applied.

Generated by OpenCVE AI on August 14, 2026 at 20:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service due to uncontrolled recursion.
Title IBM Db2 Mirror for i is affected by multiple vulnerabilities
First Time appeared Ibm
Ibm db2 Mirror For I
Weaknesses CWE-674
CPEs cpe:2.3:a:ibm:db2_mirror_for_i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm db2 Mirror For I
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Ibm Db2 Mirror For I
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-14T19:20:41.832Z

Reserved: 2026-07-24T18:24:53.963Z

Link: CVE-2026-17177

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-14T20:16:50.550

Modified: 2026-08-14T20:16:50.550

Link: CVE-2026-17177

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T21:00:05Z

Weaknesses