Impact
The vulnerability is an uncontrolled recursion that can cause IBM Db2 Mirror for i to crash, resulting in a denial of service. The flaw is classified as CWE-674 and enables a remote attacker to trigger the recursion, making the database unavailable for legitimate users.
Affected Systems
IBM Db2 Mirror for i version 7.4, 7.5, and 7.6 on IBM i systems are affected. These releases are identified by the PTFs SJ10947 (7.4), SJ10961 (7.5), and SJ10948 (7.6). The vulnerability impacts all instances running these releases.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity. The description states that a remote attacker can trigger the uncontrolled recursion, implying that the attack surface is the network and that it does not require local privileges. Because the EPSS score is not available, the likelihood of exploitation in the wild cannot be quantified, but the nature of the bug suggests that exploitation is straightforward. The vulnerability is not listed in the CISA KEV catalog, so there are no known large-scale incidents recorded, but the absence of exploitation data does not mitigate the risk. Immediate patching is advised to avoid potential denial of service outages.
OpenCVE Enrichment