Sceawere

Vulnerability Detail

CVE-2026-17173UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

IBM Db2 Mirror Path Traversal Information Disclosure

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
3h ago
Vendor
IBM
Product
Db2 Mirror for i
Attack Type
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of file paths.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-08-14T20:16:50.307Z",
  "pubdate": "2026-08-14T20:16:50.307Z",
  "executiveSummary": "IBM Db2 Mirror for i contains an information disclosure vulnerability arising from the improper validation of file paths. This flaw allows a remote authenticated attacker to bypass intended access restrictions and retrieve sensitive system data.\nThe vulnerability affects IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6. Successful exploitation of this security deficiency requires the attacker to possess authenticated access to the target environment. Upon successful exploitation, the attacker can leverage path traversal mechanisms to read arbitrary files accessible to the application context, potentially exposing confidential configuration parameters, system credentials, or internal operational data.\nThe risk implications involve unauthorized data exposure and potential reconnaissance capabilities that could facilitate subsequent attacks against the host system. Remediation relies on applying official vendor patches and enforcing strict access controls to limit user privileges and network exposure.",
  "technicalDetails": "The vulnerability resides within the file processing logic of IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6. The root cause is the improper validation and sanitization of user-supplied input utilized in file path construction. Specifically, the application fails to adequately filter directory traversal sequences, such as dot-dot-slash patterns, allowing malicious input to manipulate the intended directory context.\nTo exploit this vulnerability, a remote attacker must first authenticate to the system with valid credentials. The attacker then interacts with the vulnerable component by supplying a crafted request containing specially manipulated file paths. Due to the lack of stringent path validation, the application resolves the malicious path outside the designated secure root directory.\nDuring the attack flow, the vulnerable function processes the unsanitized input and attempts to access the targeted file system resource. Because access control checks rely on flawed path validation, the system reads the requested file and returns its contents within the application response payload. The post-exploitation impact is characterized by unauthorized information disclosure, enabling the retrieval of sensitive files residing on the underlying file system.\nThe attack vector is network-based, requiring remote connectivity and authenticated access. No specific high-privilege administrative capabilities are inherently required beyond baseline authentication, provided the authenticated user can invoke the affected component. The payload behavior centers on reading arbitrary data streams rather than executing arbitrary code, limiting the direct impact to confidentiality breaches."
}
CVE-2026-17173: IBM Db2 Mirror Path Traversal Information Disclosure (MEDIUM Severity, CVSS: 6.5) - Sceawere