CVE-2026-17081
8.2IBM · Db2 Mirror for i
A path traversal vulnerability exists in IBM Db2 Mirror for i, allowing an unauthenticated remote attacker to perform unauthorized file operations on the system.
Executive summary
An unauthenticated path traversal vulnerability in IBM Db2 Mirror for i allows for unauthorized file system manipulation and potential service disruption.
Vulnerability
The software fails to properly limit pathnames to restricted directories (CWE-22), which permits an unauthenticated attacker to traverse the file system. This can lead to unauthorized modification of critical system files or impact service availability.
Business impact
With a CVSS score of 8.2, this vulnerability represents a significant threat to data integrity. An attacker could potentially modify or corrupt essential files, leading to system instability or the unauthorized alteration of database configurations, which could result in severe operational downtime and loss of trust in data accuracy.
Remediation
Immediate Action: Apply the required PTF for your version: SJ10947 (7.4), SJ10961 (7.5), or SJ10948 (7.6) as soon as possible.
Proactive Monitoring: Review file integrity logs and system access reports for anomalous path access attempts or unexpected file modifications.
Compensating Controls: Use network access control lists (ACLs) to restrict access to the affected service to only necessary management workstations.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
The risk to system integrity is high, and the vulnerability is reachable without authentication. Administrators must treat this update with urgency to prevent potential file system manipulation that could compromise the entire database mirroring environment.