Description
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 IBM i could allow a local attacker to delete historical flight-recorder archives due to improper access control in an SQL procedure.
Published: 2026-09-04
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Deletion of historical flight‑recorder archives
Action: Apply Patch
AI Analysis

Impact

The vulnerability is an improper authorization flaw in a database SQL procedure that permits a local attacker to delete historic flight‑recorder archives stored by Db2 Mirror for i. The impact is a loss of integrity for the archived data, potentially obscuring critical operational logs. Because the bug is activated by executing the specific procedure, the damage is limited to the scope of the mirrored database and its stored archives, but the absence of those logs can hinder troubleshooting and forensic investigations.

Affected Systems

IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6 are affected. The fix is distributed in IBM i release specific PTFs: for 7.4 the PTFs are SJ11153, SJ11193, and SJ11207; for 7.5 they are SJ11152, SJ11194, and SJ11206; for 7.6 they are SJ11151, SJ11195, and SJ11205.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting current exploitation risk is limited. The likely attack vector is local; an attacker must reach the IBM i system with sufficient privileges to run the SQL procedure or to execute the PTFs. Real‑world exploits are not reported, so the primary risk is that a legitimate or compromised local user could intentionally or accidentally erase historical flight records.

Generated by OpenCVE AI on September 4, 2026 at 18:07 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release 5770-SS1 PTF Numbers PTF Download Link 7.4 SJ11153 SJ11193 SJ11207 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11153 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11193 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11207 7.5 SJ11152  SJ11194 SJ11206 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11152 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11194 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11206 7.6 SJ11151 SJ11195 SJ11205 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11151 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11195 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ11205 https://www.ibm.com/support/fixcentral


OpenCVE Recommended Actions

  • Apply the IBM i PTFs for Db2 Mirror for i corresponding to the affected release (SJ11153, SJ11193, SJ11207 for 7.4; SJ11152, SJ11194, SJ11206 for 7.5; SJ11151, SJ11195, SJ11205 for 7.6).
  • Review the database role permissions and ensure that only authorized roles can invoke the deletion procedure; remove or restrict any unnecessary privileges.
  • Limit local OS user access to the Db2 Mirror for i service and the directories containing the flight‑recorder archives, applying role‑based access controls or firewall rules as appropriate.

Generated by OpenCVE AI on September 4, 2026 at 18:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ibm:db2_mirror_for_i:*:*:*:*:*:*:*:*

Fri, 04 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description IBM Db2 Mirror for i 7.4, 7.5, and 7.6 IBM i could allow a local attacker to delete historical flight-recorder archives due to improper access control in an SQL procedure.
Title IBM Db2 Mirror for i is affected by multiple vulnerabilities [, , ]
First Time appeared Ibm
Ibm db2 Mirror For I
Weaknesses CWE-285
CPEs cpe:2.3:a:ibm:db2_mirror_for_i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm db2 Mirror For I
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Ibm Db2 Mirror For I
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-10T15:06:50.597Z

Reserved: 2026-07-25T23:05:40.415Z

Link: CVE-2026-17483

cve-icon Vulnrichment

Updated: 2026-09-09T18:27:33.069Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-04T17:16:54.777

Modified: 2026-09-10T16:17:08.607

Link: CVE-2026-17483

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T21:00:12Z

Weaknesses