Description
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory.
Published: 2026-08-14
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows a remote authenticated attacker to access sensitive data by exploiting improper limitation of a pathname to a restricted directory, which effectively enables reading of files outside the intended directory. This path traversal flaw is classified as CWE‑22 and can lead to the disclosure of confidential information stored on the system. The attack can be performed over the network once the attacker has valid credentials to the Db2 Mirror service, and the impact is the compromise of data confidentiality for the compromised user account.

Affected Systems

The affected product is IBM Db2 Mirror for i for the IBM i platform. Versions 7.4, 7.5, and 7.6 are vulnerable; the corresponding IBM PTFs are SJ10947 for 7.4, SJ10961 for 7.5, and SJ10948 for 7.6.

Risk and Exploitability

The CVSS score is 7.5, indicating a high severity for potential information disclosure. EPSS data is not available and the flaw is not listed in the CISA KEV catalog, but the remote authenticated attack vector still poses a significant risk. Prompt remediation is recommended to prevent unauthorized data access for authenticated users.

Generated by OpenCVE AI on August 14, 2026 at 20:37 UTC.

Remediation

Vendor Solution

IBM strongly recommends addressing the vulnerability now. IBM i Release 5770-DBM PTF Numbers PTF Download Link 7.4 SJ10947 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10947 7.5 SJ10961 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10961 7.6 SJ10948 https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10948 https://www.ibm.com/support/fixcentral


OpenCVE Recommended Actions

  • Download and install the IBM patch that matches your installed Db2 Mirror version from IBM Fix Central (for example, SJ10947 for 7.4, SJ10961 for 7.5, or SJ10948 for 7.6).
  • Restart the Db2 Mirror service so the patch takes effect and confirm the application is functioning normally after deployment.
  • Audit user accounts that have authenticated access to Db2 Mirror and limit privileges to only those necessary, reducing the attack surface for any future authentication‑based exploits.

Generated by OpenCVE AI on August 14, 2026 at 20:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory.
Title IBM Db2 Mirror for i is affected by multiple vulnerabilities
First Time appeared Ibm
Ibm db2 Mirror For I
Weaknesses CWE-22
CPEs cpe:2.3:a:ibm:db2_mirror_for_i:7.4.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.6.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2_mirror_for_i:7.6:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm db2 Mirror For I
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Ibm Db2 Mirror For I
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-14T19:23:50.724Z

Reserved: 2026-08-01T07:21:43.547Z

Link: CVE-2026-18554

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-14T20:16:51.720

Modified: 2026-08-14T20:16:51.720

Link: CVE-2026-18554

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T21:15:05Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')