Impact
The vulnerability arises from the improper validation of request URI path segments in IBM Db2 Mirror for i, which allows a remote attacker to bypass authentication controls and read or modify sensitive information within the system. This flaw effectively grants an unauthenticated user the ability to exploit the application’s privilege enforcement, resulting in potential data theft, unauthorized modification, or privacy violations.
Affected Systems
IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6 are affected by this issue.
Risk and Exploitability
With a CVSS score of 9.8 the flaw is considered critical, and the EPSS score is not available. The vulnerability is not yet listed in CISA’s KEV catalog, indicating no publicly confirmed exploits. The description implies a remote attack vector where an attacker can craft a special URI path segment to service requests, thereby bypassing authentication without requiring local access or additional privileges.
OpenCVE Enrichment