CVE-2026-16915

7.5

IBM · Db2 Mirror for i

A path traversal vulnerability in IBM Db2 Mirror for i allows an unauthenticated remote attacker to read sensitive files from the underlying system.

Executive summary

An unauthenticated path traversal vulnerability in IBM Db2 Mirror for i enables unauthorized access to sensitive system files, posing a severe risk to data confidentiality.

Vulnerability

This vulnerability is a path traversal flaw (CWE-22) that allows an unauthenticated attacker to bypass directory restrictions and access files outside of the intended scope. This provides a direct path for the exfiltration of sensitive configuration or system data.

Business impact

The CVSS score of 7.5 highlights a high risk to data confidentiality. Unauthorized access to system files can lead to the exposure of credentials, database structures, or proprietary business logic, potentially resulting in regulatory non-compliance and reputational damage.

Remediation

Immediate Action: Deploy the vendor-supplied PTFs immediately: SJ10947 for version 7.4, SJ10961 for version 7.5, or SJ10948 for version 7.6.

Proactive Monitoring: Analyze network traffic and system access logs for directory traversal sequences, such as dot-dot-slash patterns, directed at the Db2 Mirror interface.

Compensating Controls: Implement strict firewall rules to block unauthorized external access to the management interfaces of the Db2 Mirror system.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

The ability for an unauthenticated user to read arbitrary files is a critical security failure. Administrators are urged to apply the recommended patches immediately to secure the database environment against unauthorized information disclosure.

More IBM CVEs