Executive brief
IBM Db2 Mirror for i is a database replication tool used to synchronize data across systems. A SQL injection vulnerability allows authenticated users to bypass security controls by injecting malicious SQL commands, potentially leading to unauthorized data access or modification.
Technical details
This vulnerability is a SQL injection (CWE-89) resulting from improper neutralization of special elements in SQL commands. The flaw requires authentication and network access to the Db2 Mirror for i interface. An authenticated attacker can craft specially-formed SQL commands to bypass authorization checks and access or modify data beyond their permitted scope. The vulnerability affects versions 7.4, 7.5, and 7.6. Patch availability should be verified through IBM security bulletins.
Affected products
- IBM Db2 Mirror for i 7.4, 7.5, 7.6
Timeline
- 2026-08-14: disclosed