Impact
The vulnerability allows a remote authenticated attacker to access sensitive data by exploiting improper limitation of a pathname to a restricted directory, which effectively enables reading of files outside the intended directory. This path traversal flaw is classified as CWE‑22 and can lead to the disclosure of confidential information stored on the system. The attack can be performed over the network once the attacker has valid credentials to the Db2 Mirror service, and the impact is the compromise of data confidentiality for the compromised user account.
Affected Systems
The affected product is IBM Db2 Mirror for i for the IBM i platform. Versions 7.4, 7.5, and 7.6 are vulnerable; the corresponding IBM PTFs are SJ10947 for 7.4, SJ10961 for 7.5, and SJ10948 for 7.6.
Risk and Exploitability
The CVSS score is 7.5, indicating a high severity for potential information disclosure. EPSS data is not available and the flaw is not listed in the CISA KEV catalog, but the remote authenticated attack vector still poses a significant risk. Prompt remediation is recommended to prevent unauthorized data access for authenticated users.
OpenCVE Enrichment