Executive brief
IBM Db2 Mirror for i is a database management interface for IBM's i operating system. An authenticated attacker can bypass security restrictions due to improper authorization checks, potentially gaining unauthorized access to sensitive database functions and data. This vulnerability requires valid credentials but allows circumvention of access controls once inside the system.
Technical details
The vulnerability is an authorization bypass (CWE-285: Improper Authorization) in Db2 Mirror for i that allows an authenticated remote attacker to bypass security restrictions through improper validation of user-supplied input. The flaw is in how the application enforces access control; a legitimate user with credentials can craft requests that circumvent authorization checks intended to restrict certain operations. The attack requires valid authentication credentials and network access to the Db2 Mirror for i interface, but no special user interaction. An attacker can use this to access data or perform operations beyond their assigned privileges. Patches are available from IBM.
Affected products
- IBM Db2 Mirror for i 7.4, 7.5, 7.6
Timeline
- 2026-08-14: disclosed