CVE-2026-17184

9.8

IBM · Db2 Mirror for i

IBM Db2 Mirror for i contains a path traversal vulnerability that allows remote, unauthenticated attackers to execute arbitrary code through external control of file names or paths.

Executive summary

A critical file path control vulnerability in IBM Db2 Mirror for i allows unauthenticated remote attackers to achieve arbitrary code execution.

Vulnerability

The vulnerability involves the External Control of File Name or Path (CWE-73), which is being leveraged to trigger arbitrary code execution. The attack is network based and requires no authentication.

Business impact

Successful exploitation allows an attacker to gain control over the underlying system, leading to total system compromise. This poses a catastrophic risk to business operations, as attackers could deploy malware, steal sensitive credentials, or destroy critical database records. The CVSS score of 9.8 underscores the necessity for immediate defensive action.

Remediation

Immediate Action: Apply the vendor-provided PTF immediately: SJ10947 for version 7.4, SJ10961 for version 7.5, or SJ10948 for version 7.6.

Proactive Monitoring: Monitor system logs for attempts to access or execute files outside of the expected application directories.

Compensating Controls: Utilize a Web Application Firewall (WAF) to inspect and block malicious URI patterns or path traversal attempts directed at the application.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The severity of this vulnerability necessitates immediate patching. Security teams should treat this as a high priority item to prevent potential remote code execution and subsequent full system compromise.

More IBM CVEs