Impact
This vulnerability permits an attacker who has authenticated credentials to exploit a path traversal flaw within IBM Db2 Mirror for i. By constructing a malicious request that bypasses normal directory restrictions, the attacker can cause the system to delete arbitrary files on the host. The impact is loss of data and possible disruption of database operations. It is specifically a CWE-22 type flaw.
Affected Systems
The affected product family is IBM Db2 Mirror for i, versions 7.4, 7.5, and 7.6. Users running any of these releases are susceptible until an IBM patch is applied. The patches are available as PTFs SJ10947 (7.4), SJ10961 (7.5), and SJ10948 (7.6).
Risk and Exploitability
The CVSS score for this issue is 5.4, indicating a medium severity. EPSS information is not currently available, so the precise likelihood of exploitation cannot be quantified, but the fact that it requires authenticated access lowers the risk compared to unauthenticated flaws. The vulnerability is not listed in the CISA KEV catalog, so there is no evidence of known public exploitation yet. An attacker would need valid user credentials for Db2 Mirror for i and would need to construct a path traversal request to delete files, which may be limited by system configuration and privileges.
OpenCVE Enrichment