Impact
IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6 contain a cross‑site scripting (XSS) flaw that permits a remote authenticated attacker to execute arbitrary scripts on the appliance. The flaw is identified as CWE‑79 and can be exploited after the attacker logs in with valid credentials. The impact of the script execution is dependent on the payload but could allow the attacker to manipulate application behavior or data stored on the system.
Affected Systems
The affected products are IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6. These versions correspond to the IBM i releases 7.4, 7.5, and 7.6 and are identified by the PTF numbers SJ10947 (7.4), SJ10961 (7.5), and SJ10948 (7.6).
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity. The EPSS score is not available, so the likelihood of exploitation cannot be quantified. The vulnerability is not listed in CISA KEV. Attackers need remote authenticated access; once authenticated, the XSS flaw permits execution of arbitrary scripts, which could lead to consequences ranging from data alteration to service disruption, depending on the attacker’s intent and the scripts injected.
OpenCVE Enrichment