Sceawere
Vulnerability Detail
CVE-2026-17175UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
IBM Db2 Mirror Information Disclosure
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 3h ago
- Vendor
- IBM
- Product
- Db2 Mirror for i
- Attack Type
- CWE-287 Improper Authentication
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication enforcement.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-08-14T20:16:50.430Z",
"pubdate": "2026-08-14T20:16:50.430Z",
"executiveSummary": "A vulnerability exists in IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6 that can allow a remote authenticated attacker to obtain sensitive information.\nThe security flaw stems from improper authentication enforcement within the affected product.\nSuccessful exploitation of this vulnerability compromises the confidentiality of stored or processed data, enabling unauthorized retrieval of sensitive system or application information without requiring elevated privileges beyond basic authentication.\nThe risk implication is moderate to high depending on the sensitivity of the data exposed via the improperly secured functionality.\nAttackers must possess valid credentials to authenticate against the target environment, after which they can leverage the authentication enforcement flaw to bypass intended access controls and extract protected information.\nNo specific preconditions beyond remote network connectivity and valid authentication credentials are explicitly detailed in the advisory.",
"technicalDetails": "The root cause of the vulnerability resides in improper authentication enforcement within IBM Db2 Mirror for i.\nThe affected component fails to adequately validate or enforce access control decisions during specific remote requests, creating a broken authentication or authorization state.\nAffected versions comprise IBM Db2 Mirror for i 7.4, 7.5, and 7.6.\nThe vulnerability requires the attacker to be authenticated remotely to interact with the vulnerable service.\nAlthough authentication is required, the privilege level necessary to exploit the flaw is bounded by the improper enforcement mechanism, potentially allowing standard authenticated users to access resources or data intended for restricted or privileged contexts.\nThe network exposure is remote, meaning an attacker with network access to the vulnerable Db2 Mirror endpoints can initiate the attack vector.\nThe attack flow proceeds as follows: First, the remote attacker establishes a connection to the vulnerable IBM Db2 Mirror service utilizing valid authentication credentials. Second, the attacker issues specially crafted requests or queries directed at the improperly protected component or function. Third, because the underlying architecture fails to properly verify authorization boundaries and enforcement checks for the requested operation, the system processes the request as valid. Finally, the service responds by returning sensitive data to the attacker, leading to unauthorized information disclosure.\nPost-exploitation impact is primarily centered on confidentiality loss, where the illicitly obtained sensitive information can be leveraged by the attacker to plan further attacks, compromise related database components, or expose proprietary data residing within the Db2 Mirror environment."
}