Impact
IBM Db2 Mirror for i contains a command injection flaw (CWE-78) that can be triggered by a remote authenticated attacker. The audit reveals that the flaw could lead to a denial of service by terminating or disabling the Db2 Mirror service. The issue occurs when the service processes untrusted input that is then treated as a system command, causing the replication engine to fail and the database to become unreachable. The flaw requires authentication to the Db2 Mirror environment; therefore, attackers must possess valid credentials before exploitation is possible. While the description does not confirm the execution of arbitrary commands, it is inferred that the injection could potentially allow arbitrary command execution, but this is not explicitly documented.
Affected Systems
The flaw affects IBM Db2 Mirror for i releases 7.4, 7.5, and 7.6. IBM recommends applying PTF SJ10947 for version 7.4, PTF SJ10961 for version 7.5, and PTF SJ10948 for version 7.6 as the authoritative fixes.
Risk and Exploitability
The CVSS score of 8.5 classifies this issue as a high severity vulnerability. The EPSS score is currently unavailable but the lack of listing in the CISA KEV catalog suggests no confirmed public exploits have been reported yet. Because the flaw requires authentication, the risk is confined to environments where credentials are compromised; however, the denial of service impact can be critical to business operations.
OpenCVE Enrichment