Multiple security vulnerabilities affecting IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6, including a remote code execution flaw with a CVSS score of 9.9, allowing an attacker to run system commands without logging in.
CVE-2026-17186 (CVSS 9.9 — Severity): This vulnerability lets a remote attacker slip extra CL commands into a request, which the GUI fails to filter before running them, resulting in arbitrary code execution.[/subscribe_to_unlock_form]
Multiple security vulnerabilities affecting IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6, including a remote code execution flaw with a CVSS score of 9.9, allowing an attacker to run system commands without logging in.
CVE-2026-17186 (CVSS 9.9 — Severity): This vulnerability lets a remote attacker slip extra CL commands into a request, which the GUI fails to filter before running them, resulting in arbitrary code execution.[emaillocker id="1283"]
CVE-2026-17184 (CVSS 9.8 — Severity): This bug allows an attacker to control a file path used by the system, leading to arbitrary code execution due to path confusion.
CVE-2026-17182 (CVSS 9.8 — Severity): An attacker can skip login entirely by sending a crafted request path, allowing unauthenticated network access and potentially exposing sensitive system data.
CVE-2026-17181 (CVSS 9.3 — Severity): This vulnerability lets an attacker read or write files outside their intended folder, adding to the overall risk of sensitive system data exposure.
CVE-2026-16879 (CVSS 8.8 — Severity): A SQL injection bug is present in this version, allowing an attacker to manipulate database queries and potentially extract sensitive information.
CVE-2026-17179 (CVSS 8.5 — Severity): This vulnerability involves a cross-site scripting flaw, enabling an attacker to inject malicious code into the system, potentially leading to unauthorized access or data tampering.
CVE-2026-16708 (CVSS 8.3 — Severity): A denial-of-service bug is present in this version, allowing an attacker to disrupt system operations and cause service unavailability.
CVE-2026-17081 (CVSS 8.2 — Severity): This vulnerability involves a command injection flaw, enabling an attacker to inject malicious commands into the system, potentially leading to unauthorized access or data tampering.
These vulnerabilities collectively present a significant risk to organizations running IBM Db2 Mirror for i, particularly those in banking, retail, or logistics operations where mirrored systems are critical.
We recommend you to update Db2 Mirror for i to the version SJ10947 on 7.4, SJ10961 on 7.5, or SJ10948 on 7.6.
The following reports contain further technical details:
[/emaillocker]