Impact
The vulnerability is a path traversal flaw that allows a remote attacker to write files to arbitrary locations on the host where IBM Db2 Mirror for i is installed. This flaw can be used to place unauthorized files or alter configuration data, potentially compromising system integrity. The weakness is documented as CWE‑22, which indicates improper handling of absolute or relative paths provided by the user.
Affected Systems
IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6 are affected. The fix is provided in IBM PTFs SJ10947 for 7.4, SJ10961 for 7.5, and SJ10948 for 7.6.
Risk and Exploitability
The CVSS score of 9.3 classifies this flaw as Critical. The EPSS score is not available, but the lack of a KEV listing does not diminish the potential for exploitation. The path traversal vulnerability can be triggered remotely, implying that an attacker with network access to the Db2 Mirror for i service could exploit it without needing local credentials. Given the high severity and the remote attack vector, the risk of exploitation is high.
OpenCVE Enrichment