Executive brief
IBM Db2 Mirror for i is a database replication and disaster recovery tool used to protect business-critical data on IBM i systems. A cross-site request forgery (CSRF) vulnerability in the product's web GUI allows a remote attacker to trick authenticated users into performing unintended actions, potentially exposing sensitive database information or modifying system configurations. The vulnerability requires user interaction and affects versions 7.4, 7.5, and 7.6.
Technical details
This is a cross-site request forgery (CSRF) vulnerability (CWE-352) in the IBM Db2 Mirror for i GUI caused by improper request validation. The vulnerability is network-accessible and requires user interaction (the victim must be tricked into clicking a malicious link while authenticated to the GUI), but does not require authentication from the attacker. An attacker can craft a malicious web page that, when visited by an authenticated GUI user, forces the user's browser to submit unauthorized requests to the Db2 Mirror for i interface, allowing the attacker to obtain sensitive information or potentially modify configurations. IBM has released patches for affected versions: PTF SJ11335 (7.4), SJ11336 (7.5), and SJ11337 (7.6).
Affected products
- IBM Db2 Mirror for i 7.4, 7.5, 7.6
Timeline
- 2026-09-10: disclosed
- 2026-09-10: patched: PTF releases available: SJ11335 (7.4), SJ11336 (7.5), SJ11337 (7.6)