CVE-2026-17175
7.5IBM · Db2 Mirror for i
IBM Db2 Mirror for i contains an improper authentication vulnerability that may allow unauthenticated remote attackers to gain unauthorized access to sensitive information.
Executive summary
An improper authentication vulnerability in IBM Db2 Mirror for i 7.4, 7.5, and 7.6 poses a high risk of unauthorized information disclosure to unauthenticated remote attackers.
Vulnerability
This issue is classified as CWE-287, Improper Authentication. It allows an unauthenticated remote attacker to bypass security controls and access sensitive data, as the application fails to correctly verify the identity of the user.
Business impact
Successful exploitation of this vulnerability can lead to the unauthorized exposure of sensitive data processed by the Db2 Mirror environment. With a CVSS score of 7.5, this high-severity flaw represents a significant risk to data confidentiality and regulatory compliance, necessitating immediate remediation to prevent potential data breaches.
Remediation
Immediate Action: Administrators must apply the relevant Program Temporary Fix (PTF) for their specific IBM i release: SJ10947 for 7.4, SJ10961 for 7.5, or SJ10948 for 7.6.
Proactive Monitoring: Review system access logs for unusual or unauthorized connection attempts, particularly those originating from unexpected network segments.
Compensating Controls: Ensure that access to the Db2 Mirror management interface is restricted to authorized administrative networks using IP allowlisting and network segmentation.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the high CVSS score and the potential for unauthorized data access, organizations should prioritize the deployment of the provided IBM PTF updates. Applying these patches is the only reliable method to eliminate the underlying authentication weakness.