Impact
IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6 contain an SQL injection flaw (CWE‑89) that allows a remote authenticated attacker to insert special characters into an SQL command, thereby bypassing existing security controls. The flaw arises from improper neutralization of these characters and can lead to the attacker gaining elevated privileges or accessing data that should be protected.
Affected Systems
Affected products include IBM Db2 Mirror for i, specifically the 7.4, 7.5, and 7.6 releases. The vulnerability applies to all patch level builds of these versions as indicated by the corresponding IBM PTF numbers and download links provided by IBM.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate overall severity, with the description highlighting that remote authentication is required. EPSS data is not available and the vulnerability is not yet listed in CISA KEV, suggesting a lower but not negligible exploitation likelihood. Attackers would need valid credentials against the database system and can then manipulate input to escape intended restrictions. Once the flaw is exploited, the attacker can execute arbitrary SQL and potentially elevate privileges or access confidential data.
OpenCVE Enrichment