Ibm Db2 Mirror For I vulnerabilities
28 known vulnerabilities affecting ibm/db2_mirror_for_i.
Total CVEs
28
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH8MEDIUM14LOW2
Vulnerabilities
Page 2 of 2
CVE-2026-17209P4MEDIUMCVSS 5.4≥ 7.4, ≤ 7.6v7.4+2 more2026-08-14
CVE-2026-17209 [MEDIUM] CWE-79 CVE-2026-17209: IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to execute arbitr
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to execute arbitrary scripts due to cross-site scripting.
nvd
CVE-2026-16660P4MEDIUMCVSS 5.3≥ 7.4, ≤ 7.6v7.4+2 more2026-09-04
CVE-2026-16660 [MEDIUM] CWE-125 CVE-2026-16660: IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service du
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service due to an out-of-bounds read.
nvd
CVE-2026-17047P4MEDIUMCVSS 5.4v7.4v7.5+1 more2026-09-14
CVE-2026-17047 [MEDIUM] CWE-352 CVE-2026-17047: IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to obtain sensitive information
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to obtain sensitive information due to improper request validation.
nvd
CVE-2026-17079P4MEDIUMCVSS 4.3≥ 7.4, ≤ 7.6v7.4+2 more2026-08-14
CVE-2026-17079 [MEDIUM] CWE-693 CVE-2026-17079: IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass securit
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to the ability to disable server-side input validation via a request parameter.
nvd
CVE-2023-47741P4MEDIUMCVSS 5.3v7.4v7.5+1 more2023-12-18
CVE-2023-47741 [MEDIUM] CWE-522 CVE-2023-47741: IBM i 7.3, 7.4, 7.5, IBM i Db2 Mirror for i 7.4 and 7.5 web browser clients may leave clear-text pa
IBM i 7.3, 7.4, 7.5, IBM i Db2 Mirror for i 7.4 and 7.5 web browser clients may leave clear-text passwords in browser memory that can be viewed using common browser tools before the memory is garbage collected. A malicious actor with access to the victim's PC could exploit this vulnerability to gain access to the IBM i operating system. IBM X-Force I
nvd
CVE-2026-18567P4MEDIUMCVSS 4.7≥ 7.4, ≤ 7.6v7.4+2 more2026-09-04
CVE-2026-18567 [MEDIUM] CWE-367 CVE-2026-18567: IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a local attacker to obtain information due to a r
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a local attacker to obtain information due to a race condition involving a predictable Unix domain socket path in a world-writable directory.
nvd
CVE-2026-17483P4LOWCVSS 3.3≥ 7.4, ≤ 7.6v7.4+2 more2026-09-04
CVE-2026-17483 [LOW] CWE-285 CVE-2026-17483: IBM Db2 Mirror for i 7.4, 7.5, and 7.6 IBM i could allow a local attacker to delete historical fligh
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 IBM i could allow a local attacker to delete historical flight-recorder archives due to improper access control in an SQL procedure.
nvd
CVE-2026-18104P4LOWCVSS 3.3≥ 7.4, ≤ 7.6v7.6+2 more2026-09-24
CVE-2026-18104 [LOW] CWE-327 CVE-2026-18104: IBM Db2 Mirror for i 7.6, 7.5, and 7.4 could allow a local attacker to obtain sensitive information
IBM Db2 Mirror for i 7.6, 7.5, and 7.4 could allow a local attacker to obtain sensitive information due to the use of the AES Electronic Codebook (ECB) mode for encryption.
nvd
← Previous2 / 2