Description
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to delete arbitrary files due to path traversal.
Published: 2026-08-14
Score: 5.4 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability permits an attacker who has authenticated credentials to exploit a path traversal flaw within IBM Db2 Mirror for i. By constructing a malicious request that bypasses normal directory restrictions, the attacker can cause the system to delete arbitrary files on the host. The impact is loss of data and possible disruption of database operations. It is specifically a CWE-22 type flaw.

Affected Systems

The affected product family is IBM Db2 Mirror for i, versions 7.4, 7.5, and 7.6. Users running any of these releases are susceptible until an IBM patch is applied. The patches are available as PTFs SJ10947 (7.4), SJ10961 (7.5), and SJ10948 (7.6).

Risk and Exploitability

The CVSS score for this issue is 5.4, indicating a medium severity. EPSS information is not currently available, so the precise likelihood of exploitation cannot be quantified, but the fact that it requires authenticated access lowers the risk compared to unauthenticated flaws. The vulnerability is not listed in the CISA KEV catalog, so there is no evidence of known public exploitation yet. An attacker would need valid user credentials for Db2 Mirror for i and would need to construct a path traversal request to delete files, which may be limited by system configuration and privileges.

Generated by OpenCVE AI on August 14, 2026 at 20:37 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release 5770-DBM PTF Numbers PTF Download Link 7.4 SJ10947 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10947 7.5 SJ10961 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10961 7.6 SJ10948 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10948 https://www.ibm.com/support/fixcentral


OpenCVE Recommended Actions

  • Download and install the IBM PTF specific to your Db2 Mirror for i release (SJ10947 for 7.4, SJ10961 for 7.5, or SJ10948 for 7.6).
  • Follow IBM’s installation instructions to apply the patch, ensuring the affected components are updated and, if required, reboot the system.
  • If immediate patch deployment is not feasible, enforce strict file system permissions and limit the rights of authenticated users over directories accessed by Db2 Mirror for i to prevent unauthorized deletion.

Generated by OpenCVE AI on August 14, 2026 at 20:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to delete arbitrary files due to path traversal.
Title IBM Db2 Mirror for i is affected by multiple vulnerabilities
First Time appeared Ibm
Ibm db2 Mirror For I
Weaknesses CWE-22
CPEs cpe:2.3:a:ibm:db2_mirror_for_i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm db2 Mirror For I
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

Ibm Db2 Mirror For I
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-14T19:23:30.515Z

Reserved: 2026-07-28T22:44:58.243Z

Link: CVE-2026-18178

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-14T20:16:51.487

Modified: 2026-08-14T20:16:51.487

Link: CVE-2026-18178

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T20:45:03Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')