Description
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to execute arbitrary scripts due to cross-site scripting.
Published: 2026-08-14
Score: 6.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6 contain a cross‑site scripting (XSS) flaw that permits a remote authenticated attacker to execute arbitrary scripts on the appliance. The flaw is identified as CWE‑79 and can be exploited after the attacker logs in with valid credentials. The impact of the script execution is dependent on the payload but could allow the attacker to manipulate application behavior or data stored on the system.

Affected Systems

The affected products are IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6. These versions correspond to the IBM i releases 7.4, 7.5, and 7.6 and are identified by the PTF numbers SJ10947 (7.4), SJ10961 (7.5), and SJ10948 (7.6).

Risk and Exploitability

The CVSS score of 6.3 indicates moderate severity. The EPSS score is not available, so the likelihood of exploitation cannot be quantified. The vulnerability is not listed in CISA KEV. Attackers need remote authenticated access; once authenticated, the XSS flaw permits execution of arbitrary scripts, which could lead to consequences ranging from data alteration to service disruption, depending on the attacker’s intent and the scripts injected.

Generated by OpenCVE AI on August 14, 2026 at 21:23 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release 5770-DBM PTF Numbers PTF Download Link 7.4 SJ10947 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10947 7.5 SJ10961 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10961 7.6 SJ10948 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10948 https://www.ibm.com/support/fixcentral


OpenCVE Recommended Actions

  • Apply the IBM Fix Central PTF for the affected version (SJ10947 for 7.4, SJ10961 for 7.5, or SJ10948 for 7.6).
  • If a patch cannot be applied immediately, deny external web access to the Db2 Mirror for i appliance or restrict authenticated user roles to prevent script execution until remediation.
  • Implement a temporary web application firewall rule or input sanitization to block malicious script payloads targeting the database mirror interface.

Generated by OpenCVE AI on August 14, 2026 at 21:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to execute arbitrary scripts due to cross-site scripting.
Title IBM Db2 Mirror for i is affected by multiple vulnerabilities
First Time appeared Ibm
Ibm db2 Mirror For I
Weaknesses CWE-79
CPEs cpe:2.3:a:ibm:db2_mirror_for_i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm db2 Mirror For I
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:N'}


Subscriptions

Ibm Db2 Mirror For I
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-14T19:22:58.619Z

Reserved: 2026-07-24T19:40:20.743Z

Link: CVE-2026-17209

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-14T20:16:51.250

Modified: 2026-08-14T20:16:51.250

Link: CVE-2026-17209

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T21:30:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')