Description
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to cause a denial of service due to command injection.
Published: 2026-08-14
Score: 8.5 High
EPSS: 1.2% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A command injection flaw (CWE‑78) in IBM Db2 Mirror for i 7.4, 7.5, and 7.6 can be triggered by a remote authenticated attacker. The flaw may lead to a denial‑of‑service by affecting the Db2 Mirror service. The CVE description does not detail the specific commands that could be executed, only that injection could cause a service outage.

Affected Systems

The flaw affects IBM Db2 Mirror for i releases 7.4, 7.5, and 7.6. IBM recommends applying PTF SJ10947 for version 7.4, PTF SJ10961 for version 7.5, and PTF SJ10948 for version 7.6 as the authoritative fixes.

Risk and Exploitability

The CVSS score of 8.5 classifies this issue as high severity. The EPSS score is 1% and the vulnerability is not listed in the CISA KEV catalog, indicating that no confirmed public exploits have been reported yet. Because the flaw requires authentication, the risk is limited to environments where credentials are compromised; nevertheless, the denial of service impact can severely disrupt business operations.

Generated by OpenCVE AI on August 24, 2026 at 16:10 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release 5770-DBM PTF Numbers PTF Download Link 7.4 SJ10947 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10947 7.5 SJ10961 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10961 7.6 SJ10948 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10948 https://www.ibm.com/support/fixcentral


OpenCVE Recommended Actions

  • Apply the IBM Fix that matches your Db2 Mirror for i release - SJ10947 for 7.4, SJ10961 for 7.5, or SJ10948 for 7.6.
  • Restart the Db2 Mirror service to ensure the patch takes effect.
  • Perform a health check to confirm that command injection no longer triggers a service outage; if issues persist, contact IBM support for further assistance.

Generated by OpenCVE AI on August 24, 2026 at 16:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ibm:db2_mirror_for_i:*:*:*:*:*:*:*:*

Mon, 17 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 14 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to cause a denial of service due to command injection.
Title IBM Db2 Mirror for i is affected by multiple vulnerabilities
First Time appeared Ibm
Ibm db2 Mirror For I
Weaknesses CWE-78
CPEs cpe:2.3:a:ibm:db2_mirror_for_i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm db2 Mirror For I
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H'}


Subscriptions

Ibm Db2 Mirror For I
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-17T20:10:45.376Z

Reserved: 2026-07-24T18:30:16.970Z

Link: CVE-2026-17179

cve-icon Vulnrichment

Updated: 2026-08-17T20:10:39.778Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-14T20:16:50.663

Modified: 2026-08-20T21:11:17.767

Link: CVE-2026-17179

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T16:15:04Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')