Threat Advisory

IBM Db2 Mirror for i Hit by RCE Flaw Lets Attackers Read Arbitrary Files

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6, including a remote code execution flaw with a CVSS score of 9.9, allowing an attacker to run system commands without logging in.

CVE-2026-17186 (CVSS 9.9 — Severity): This vulnerability lets a remote attacker slip extra CL commands into a request, which the GUI fails to filter before running them, resulting in arbitrary code execution.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6, including a remote code execution flaw with a CVSS score of 9.9, allowing an attacker to run system commands without logging in.

CVE-2026-17186 (CVSS 9.9 — Severity): This vulnerability lets a remote attacker slip extra CL commands into a request, which the GUI fails to filter before running them, resulting in arbitrary code execution.[emaillocker id="1283"]

CVE-2026-17184 (CVSS 9.8 — Severity): This bug allows an attacker to control a file path used by the system, leading to arbitrary code execution due to path confusion.

CVE-2026-17182 (CVSS 9.8 — Severity): An attacker can skip login entirely by sending a crafted request path, allowing unauthenticated network access and potentially exposing sensitive system data.

CVE-2026-17181 (CVSS 9.3 — Severity): This vulnerability lets an attacker read or write files outside their intended folder, adding to the overall risk of sensitive system data exposure.

CVE-2026-16879 (CVSS 8.8 — Severity): A SQL injection bug is present in this version, allowing an attacker to manipulate database queries and potentially extract sensitive information.

CVE-2026-17179 (CVSS 8.5 — Severity): This vulnerability involves a cross-site scripting flaw, enabling an attacker to inject malicious code into the system, potentially leading to unauthorized access or data tampering.

CVE-2026-16708 (CVSS 8.3 — Severity): A denial-of-service bug is present in this version, allowing an attacker to disrupt system operations and cause service unavailability.

CVE-2026-17081 (CVSS 8.2 — Severity): This vulnerability involves a command injection flaw, enabling an attacker to inject malicious commands into the system, potentially leading to unauthorized access or data tampering.

These vulnerabilities collectively present a significant risk to organizations running IBM Db2 Mirror for i, particularly those in banking, retail, or logistics operations where mirrored systems are critical.

RECOMMENDATION:

We recommend you to update Db2 Mirror for i to the version SJ10947 on 7.4, SJ10961 on 7.5, or SJ10948 on 7.6.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu