Ibm Db2 Mirror For I vulnerabilities
28 known vulnerabilities affecting ibm/db2_mirror_for_i.
Total CVEs
28
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH8MEDIUM14LOW2
Vulnerabilities
Page 1 of 2
CVE-2026-16956P2CRITICALCVSS 9.8≥ 7.4, ≤ 7.6v7.4+2 more2026-08-12
CVE-2026-16956 [CRITICAL] CWE-78 CVE-2026-16956: IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary commands d
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
nvd
CVE-2026-17186P2CRITICALCVSS 9.8≥ 7.4, ≤ 7.6v7.4+2 more2026-08-14
CVE-2026-17186 [CRITICAL] CWE-78 CVE-2026-17186: IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary CL command
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary CL commands due to improper neutralization of special elements in a command.
nvd
CVE-2026-17184P2CRITICALCVSS 9.8≥ 7.4, ≤ 7.6v7.4+2 more2026-08-14
CVE-2026-17184 [CRITICAL] CWE-73 CVE-2026-17184: IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary code due t
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary code due to external control of file name or path.
nvd
CVE-2026-17182P3CRITICALCVSS 9.8≥ 7.4, ≤ 7.6v7.4+2 more2026-08-14
CVE-2026-17182 [CRITICAL] CWE-287 CVE-2026-17182: IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass authentication and ob
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass authentication and obtain or alter sensitive information due to improper validation of request URI path segments.
nvd
CVE-2026-16879P3HIGHCVSS 8.8≥ 7.4, ≤ 7.6v7.4+2 more2026-08-14
CVE-2026-16879 [HIGH] CWE-285 CVE-2026-16879: IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass securit
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization using user-supplied input.
nvd
CVE-2026-17181P3HIGHCVSS 8.6≥ 7.4, ≤ 7.6v7.4+2 more2026-08-14
CVE-2026-17181 [HIGH] CWE-22 CVE-2026-17181: IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write files to arbitrary loc
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write files to arbitrary locations due to path traversal.
nvd
CVE-2026-18178P3HIGHCVSS 8.1≥ 7.4, ≤ 7.6v7.4+2 more2026-08-14
CVE-2026-18178 [HIGH] CWE-22 CVE-2026-18178: IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to delete arbitra
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to delete arbitrary files due to path traversal.
nvd
CVE-2026-17081P3HIGHCVSS 7.5≥ 7.4, ≤ 7.6v7.4+2 more2026-08-14
CVE-2026-17081 [HIGH] CWE-22 CVE-2026-17081: IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write arbitrary files due to
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write arbitrary files due to improper limitation of a pathname to a restricted directory.
nvd
CVE-2026-18554P3HIGHCVSS 7.5≥ 7.4, ≤ 7.6v7.4+2 more2026-08-14
CVE-2026-18554 [HIGH] CWE-22 CVE-2026-18554: IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensiti
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory.
nvd
CVE-2026-16915P3HIGHCVSS 7.5≥ 7.4, ≤ 7.6v7.4+2 more2026-08-14
CVE-2026-16915 [HIGH] CWE-22 CVE-2026-16915: IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensiti
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper input validation.
nvd
CVE-2026-16708P3HIGHCVSS 7.5≥ 7.4, ≤ 7.6v7.4+2 more2026-08-14
CVE-2026-16708 [HIGH] CWE-15 CVE-2026-16708: IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to obtain sensitive information
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to obtain sensitive information due to external control of system configuration.
nvd
CVE-2026-17227P3MEDIUMCVSS 6.5≥ 7.4, ≤ 7.6v7.4+2 more2026-08-14
CVE-2026-17227 [MEDIUM] CWE-89 CVE-2026-17227: IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass securit
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to improper neutralization of special elements used in an SQL command.
nvd
CVE-2026-17179P3MEDIUMCVSS 6.5≥ 7.4, ≤ 7.6v7.4+2 more2026-08-14
CVE-2026-17179 [MEDIUM] CWE-78 CVE-2026-17179: IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to cause a denial
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to cause a denial of service due to command injection.
nvd
CVE-2026-17177P3HIGHCVSS 7.5≥ 7.4, ≤ 7.6v7.4+2 more2026-08-14
CVE-2026-17177 [HIGH] CWE-674 CVE-2026-17177: IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service du
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service due to uncontrolled recursion.
nvd
CVE-2026-17173P3MEDIUMCVSS 6.5≥ 7.4, ≤ 7.6v7.4+2 more2026-08-14
CVE-2026-17173 [MEDIUM] CWE-22 CVE-2026-17173: IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensiti
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of file paths.
nvd
CVE-2026-17175P3MEDIUMCVSS 6.5≥ 7.4, ≤ 7.6v7.4+2 more2026-08-14
CVE-2026-17175 [MEDIUM] CWE-287 CVE-2026-17175: IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensiti
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication enforcement.
nvd
CVE-2025-36116P3MEDIUMCVSS 6.3v7.4v7.5+2 more2025-07-23
CVE-2025-36116 [MEDIUM] CWE-1385 CVE-2025-36116: IBM Db2 Mirror for i 7.4, 7.5, and 7.6 GUI is affected by cross-site WebSocket hijacking vulnerabili
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 GUI is affected by cross-site WebSocket hijacking vulnerability. By sending a specially crafted request, an unauthenticated malicious actor could exploit this vulnerability to sniff an existing WebSocket connection to then remotely perform operations that the user is not allowed to perform.
nvd
CVE-2026-16905P3MEDIUMCVSS 6.5≥ 7.4, ≤ 7.6v7.4+2 more2026-08-14
CVE-2026-16905 [MEDIUM] CWE-287 CVE-2026-16905: IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensiti
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication.
nvd
CVE-2022-43928P4MEDIUMCVSS 6.5v7.4v7.5+1 more2023-04-07
CVE-2022-43928 [MEDIUM] CVE-2022-43928: The IBM Toolbox for Java (Db2 Mirror for i 7.4 and 7.5) could allow a user to obtain sensitive infor
The IBM Toolbox for Java (Db2 Mirror for i 7.4 and 7.5) could allow a user to obtain sensitive information, caused by utilizing a Java string for processing. Since Java strings are immutable, their contents exist in memory until garbage collected. This means sensitive data could be visible in memory over an indefinite amount of time. IBM has addressed this
nvd
CVE-2025-36117P4MEDIUMCVSS 6.3v7.4v7.5+2 more2025-07-23
CVE-2025-36117 [MEDIUM] CWE-384 CVE-2025-36117: IBM Db2 Mirror for i 7.4, 7.5, and 7.6 does not disallow the session id after use which could allow
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 does not disallow the session id after use which could allow an authenticated user to impersonate another user on the system.
nvd
1 / 2Next →