Description
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write files to arbitrary locations due to path traversal.
Published: 2026-08-14
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a path traversal flaw that allows a remote attacker to write files to arbitrary locations on the host where IBM Db2 Mirror for i is installed. This flaw can be used to place unauthorized files or alter configuration data, potentially compromising system integrity. The weakness is documented as CWE‑22, which indicates improper handling of absolute or relative paths provided by the user.

Affected Systems

IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6 are affected. The fix is provided in IBM PTFs SJ10947 for 7.4, SJ10961 for 7.5, and SJ10948 for 7.6.

Risk and Exploitability

The CVSS score of 9.3 classifies this flaw as Critical. The EPSS score is not available, but the lack of a KEV listing does not diminish the potential for exploitation. The path traversal vulnerability can be triggered remotely, implying that an attacker with network access to the Db2 Mirror for i service could exploit it without needing local credentials. Given the high severity and the remote attack vector, the risk of exploitation is high.

Generated by OpenCVE AI on August 14, 2026 at 20:51 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release 5770-DBM PTF Numbers PTF Download Link 7.4 SJ10947 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10947 7.5 SJ10961 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10961 7.6 SJ10948 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10948 https://www.ibm.com/support/fixcentral


OpenCVE Recommended Actions

  • Apply the IBM PTFs SJ10947 (7.4), SJ10961 (7.5), and SJ10948 (7.6) to all affected Db2 Mirror for i instances as recommended by IBM.
  • After patching, restrict file write permissions on the Db2 Mirror for i directories so that only trusted system accounts may create or modify files, following CWE‑22 mitigation guidelines.
  • Until the patch is applied, isolate the Db2 Mirror for i services from untrusted networks or block inbound traffic on the relevant ports using firewalls or network segmentation to reduce exposure.

Generated by OpenCVE AI on August 14, 2026 at 20:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write files to arbitrary locations due to path traversal.
Title IBM Db2 Mirror for i is affected by multiple vulnerabilities
First Time appeared Ibm
Ibm db2 Mirror For I
Weaknesses CWE-22
CPEs cpe:2.3:a:ibm:db2_mirror_for_i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm db2 Mirror For I
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:L'}


Subscriptions

Ibm Db2 Mirror For I
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-14T19:21:30.752Z

Reserved: 2026-07-24T18:34:52.161Z

Link: CVE-2026-17181

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-14T20:16:50.777

Modified: 2026-08-14T20:16:50.777

Link: CVE-2026-17181

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T21:00:05Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')