Impact
The vulnerability allows a remote attacker to execute arbitrary code by controlling a file name or path value supplied to IBM Db2 Mirror for i. This flaw can be exploited without access to local system resources and can lead to full compromise of the host, exposing sensitive data and enabling further attacks.
Affected Systems
IBM Db2 Mirror for i releases 7.4, 7.5, and 7.6 are affected. The corresponding PTF numbers are SJ10947 for version 7.4, SJ10961 for version 7.5, and SJ10948 for version 7.6 as published by IBM.
Risk and Exploitability
With a CVSS score of 9.8 the flaw is considered critical. EPSS data is not available and the vulnerability is not listed in CISA's KEV catalog. The likely attack vector involves a remote attacker supplying a vulnerable file name or path through an exposed interface, resulting in arbitrary code execution. The severity and lack of mitigations aside from patching make the risk high.
OpenCVE Enrichment