Junglewise Threat Intelligence

CVE-2026-17047: IBM Db2 Mirror for i CSRF in GUI

CVE-2026-17047 · Severity: medium · CVSS 5.4 · Published 2026-09-14

Executive brief

IBM Db2 Mirror for i is a database replication and disaster recovery tool used to protect business-critical data on IBM i systems. A cross-site request forgery (CSRF) vulnerability in the product's web GUI allows a remote attacker to trick authenticated users into performing unintended actions, potentially exposing sensitive database information or modifying system configurations. The vulnerability requires user interaction and affects versions 7.4, 7.5, and 7.6.

Technical details

This is a cross-site request forgery (CSRF) vulnerability (CWE-352) in the IBM Db2 Mirror for i GUI caused by improper request validation. The vulnerability is network-accessible and requires user interaction (the victim must be tricked into clicking a malicious link while authenticated to the GUI), but does not require authentication from the attacker. An attacker can craft a malicious web page that, when visited by an authenticated GUI user, forces the user's browser to submit unauthorized requests to the Db2 Mirror for i interface, allowing the attacker to obtain sensitive information or potentially modify configurations. IBM has released patches for affected versions: PTF SJ11335 (7.4), SJ11336 (7.5), and SJ11337 (7.6).

Affected products

  • IBM Db2 Mirror for i 7.4, 7.5, 7.6

Timeline

  • 2026-09-10: disclosed
  • 2026-09-10: patched: PTF releases available: SJ11335 (7.4), SJ11336 (7.5), SJ11337 (7.6)

References

Related threats