Impact
A command injection flaw (CWE‑78) in IBM Db2 Mirror for i 7.4, 7.5, and 7.6 can be triggered by a remote authenticated attacker. The flaw may lead to a denial‑of‑service by affecting the Db2 Mirror service. The CVE description does not detail the specific commands that could be executed, only that injection could cause a service outage.
Affected Systems
The flaw affects IBM Db2 Mirror for i releases 7.4, 7.5, and 7.6. IBM recommends applying PTF SJ10947 for version 7.4, PTF SJ10961 for version 7.5, and PTF SJ10948 for version 7.6 as the authoritative fixes.
Risk and Exploitability
The CVSS score of 8.5 classifies this issue as high severity. The EPSS score is 1% and the vulnerability is not listed in the CISA KEV catalog, indicating that no confirmed public exploits have been reported yet. Because the flaw requires authentication, the risk is limited to environments where credentials are compromised; nevertheless, the denial of service impact can severely disrupt business operations.
OpenCVE Enrichment