Junglewise Threat Intelligence

CVE-2026-17483: IBM Db2 Mirror for i improper authorization in SQL procedure

CVE-2026-17483 · Severity: medium · CVSS 4.3 · Published 2026-09-04

Executive brief

IBM Db2 Mirror for i is a database replication tool used to maintain synchronized copies of IBM i system databases. A vulnerability in an SQL procedure allows local attackers with basic user privileges to delete historical flight-recorder archives, which are critical diagnostic records. This could impede incident investigation, system troubleshooting, and compliance audit trails.

Technical details

The vulnerability is an improper authorization flaw (CWE-285) in an SQL procedure within IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6. A local attacker with limited privileges (PR:L) can exploit this to delete historical flight-recorder archives without proper access control checks. The attack requires local system access and authentication but no user interaction. The impact is limited to data integrity and availability of diagnostic records. IBM provides patches via PTFs (program temporary fixes) for all affected versions.

Affected products

  • IBM Db2 Mirror for i 7.4, 7.5, 7.6

Timeline

  • 2026-09-04: disclosed
  • 2026-09-01: advisory

References

Related threats