Executive brief
IBM Db2 Mirror for i is a database management system used for critical business data storage and retrieval on IBM Power Systems. An authenticated remote attacker can exploit improper file path validation to read sensitive files, potentially exposing confidential business information, database credentials, or system configuration details.
Technical details
The vulnerability is a path traversal flaw (CWE-22) in IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6 caused by improper validation of file paths. An authenticated attacker can supply specially crafted path inputs to bypass directory restrictions and access files outside intended boundaries. The vulnerability requires remote network access and valid authentication credentials. Successful exploitation allows reading arbitrary files on the system, leading to confidentiality breach. IBM has issued security patches available for affected versions.
Affected products
- IBM Db2 Mirror for i 7.4, 7.5, 7.6
Timeline
- 2026-08-14: disclosed
- 2026-08-14: advisory: CVE-2026-17173 published