Description
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary code due to external control of file name or path.
Published: 2026-08-14
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows a remote attacker to execute arbitrary code by controlling a file name or path value supplied to IBM Db2 Mirror for i. This flaw can be exploited without access to local system resources and can lead to full compromise of the host, exposing sensitive data and enabling further attacks.

Affected Systems

IBM Db2 Mirror for i releases 7.4, 7.5, and 7.6 are affected. The corresponding PTF numbers are SJ10947 for version 7.4, SJ10961 for version 7.5, and SJ10948 for version 7.6 as published by IBM.

Risk and Exploitability

With a CVSS score of 9.8 the flaw is considered critical. EPSS data is not available and the vulnerability is not listed in CISA's KEV catalog. The likely attack vector involves a remote attacker supplying a vulnerable file name or path through an exposed interface, resulting in arbitrary code execution. The severity and lack of mitigations aside from patching make the risk high.

Generated by OpenCVE AI on August 14, 2026 at 20:22 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release 5770-DBM PTF Numbers PTF Download Link 7.4 SJ10947 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10947 7.5 SJ10961 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10961 7.6 SJ10948 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10948 https://www.ibm.com/support/fixcentral


OpenCVE Recommended Actions

  • Download and install the IBM‑provided PTF for your Db2 Mirror for i release (SJ10947 for 7.4, SJ10961 for 7.5, or SJ10948 for 7.6) from IBM Support.
  • Apply the PTF and perform a clean restart of the Db2 Mirror services to ensure the update takes effect.
  • Restrict external access to any interfaces that allow file‑name or path specification until the patch is fully in place, using firewall rules or application‑level restrictions.

Generated by OpenCVE AI on August 14, 2026 at 20:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary code due to external control of file name or path.
Title IBM Db2 Mirror for i is affected by multiple vulnerabilities
First Time appeared Ibm
Ibm db2 Mirror For I
Weaknesses CWE-73
CPEs cpe:2.3:a:ibm:db2_mirror_for_i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm db2 Mirror For I
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Db2 Mirror For I
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-14T19:22:28.695Z

Reserved: 2026-07-24T18:39:37.465Z

Link: CVE-2026-17184

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-14T20:16:51.010

Modified: 2026-08-14T20:16:51.010

Link: CVE-2026-17184

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T20:45:03Z

Weaknesses
  • CWE-73

    External Control of File Name or Path