Impact
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 contain an OS command injection flaw that allows a remote attacker to execute arbitrary CL commands. The flaw results from failure to neutralize special elements in a supplied command string, enabling full system compromise. The weakness is identified as CWE-78.
Affected Systems
The affected product is IBM Db2 Mirror for i for all releases 7.4, 7.5, and 7.6 on IBM i, including the sub‑versions 7.4.0, 7.4, 7.5.0, 7.5, 7.6.0, and 7.6.
Risk and Exploitability
The CVSS score of 9.9 classifies this as critical, and while the EPSS score is not reported, the absence of a CISA KEV listing does not diminish its potential risk. Remote attackers can exploit the vulnerability by sending a crafted command string to a network service that passes input to the CL interpreter, achieving arbitrary code execution on the host. The attack requires remote connectivity to the affected service and does not benefit from privileged local access prior to exploitation.
OpenCVE Enrichment