Description
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass authentication and obtain or alter sensitive information due to improper validation of request URI path segments.
Published: 2026-08-14
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from the improper validation of request URI path segments in IBM Db2 Mirror for i, which allows a remote attacker to bypass authentication controls and read or modify sensitive information within the system. This flaw effectively grants an unauthenticated user the ability to exploit the application’s privilege enforcement, resulting in potential data theft, unauthorized modification, or privacy violations.

Affected Systems

IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6 are affected by this issue.

Risk and Exploitability

With a CVSS score of 9.8 the flaw is considered critical, and the EPSS score is not available. The vulnerability is not yet listed in CISA’s KEV catalog, indicating no publicly confirmed exploits. The description implies a remote attack vector where an attacker can craft a special URI path segment to service requests, thereby bypassing authentication without requiring local access or additional privileges.

Generated by OpenCVE AI on August 14, 2026 at 20:23 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release 5770-DBM PTF Numbers PTF Download Link 7.4 SJ10947 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10947 7.5 SJ10961 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10961 7.6 SJ10948 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10948 https://www.ibm.com/support/fixcentral


OpenCVE Recommended Actions

  • Apply the IBM PTF update for your Db2 Mirror for i version (SJ10947 for 7.4, SJ10961 for 7.5, or SJ10948 for 7.6) as specified by IBM.
  • Restrict remote network access to the Db2 Mirror service or limit connections to trusted hosts until the patch is installed.
  • After updating, monitor system logs for anomalous request paths or authentication attempts and enforce strict URI validation in additional firewall or application layer controls.

Generated by OpenCVE AI on August 14, 2026 at 20:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass authentication and obtain or alter sensitive information due to improper validation of request URI path segments.
Title IBM Db2 Mirror for i is affected by multiple vulnerabilities
First Time appeared Ibm
Ibm db2 Mirror For I
Weaknesses CWE-287
CPEs cpe:2.3:a:ibm:db2_mirror_for_i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm db2 Mirror For I
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Db2 Mirror For I
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-14T19:22:03.052Z

Reserved: 2026-07-24T18:36:58.339Z

Link: CVE-2026-17182

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-14T20:16:50.893

Modified: 2026-08-14T20:16:50.893

Link: CVE-2026-17182

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T22:15:03Z

Weaknesses