CVE-2026-16915
7.5IBM · Db2 Mirror for i
A path traversal vulnerability in IBM Db2 Mirror for i allows an unauthenticated remote attacker to read sensitive files from the underlying system.
Executive summary
An unauthenticated path traversal vulnerability in IBM Db2 Mirror for i enables unauthorized access to sensitive system files, posing a severe risk to data confidentiality.
Vulnerability
This vulnerability is a path traversal flaw (CWE-22) that allows an unauthenticated attacker to bypass directory restrictions and access files outside of the intended scope. This provides a direct path for the exfiltration of sensitive configuration or system data.
Business impact
The CVSS score of 7.5 highlights a high risk to data confidentiality. Unauthorized access to system files can lead to the exposure of credentials, database structures, or proprietary business logic, potentially resulting in regulatory non-compliance and reputational damage.
Remediation
Immediate Action: Deploy the vendor-supplied PTFs immediately: SJ10947 for version 7.4, SJ10961 for version 7.5, or SJ10948 for version 7.6.
Proactive Monitoring: Analyze network traffic and system access logs for directory traversal sequences, such as dot-dot-slash patterns, directed at the Db2 Mirror interface.
Compensating Controls: Implement strict firewall rules to block unauthorized external access to the management interfaces of the Db2 Mirror system.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
The ability for an unauthenticated user to read arbitrary files is a critical security failure. Administrators are urged to apply the recommended patches immediately to secure the database environment against unauthorized information disclosure.