Sceawere

Vulnerability Detail

CVE-2026-17184UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

IBM Db2 Mirror Path Traversal Vulnerability

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
3h ago
Vendor
IBM
Product
Db2 Mirror for i
Attack Type
CWE-73 External Control of File Name or Path
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary code due to external control of file name or path.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-08-14T20:16:51.010Z",
  "pubdate": "2026-08-14T20:16:51.010Z",
  "executiveSummary": "An external control of file name or path vulnerability exists within IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6. This security flaw allows a remote attacker to manipulate file paths and execute arbitrary code on the underlying system. The vulnerability presents significant risk implications, potentially leading to full system compromise, unauthorized data access, and disruption of critical database mirroring services. Exploitation of this flaw requires network connectivity to the affected IBM i environment, and the attacker capabilities include executing unauthorized commands or code within the security context of the vulnerable application. Organizations utilizing the affected software versions face a high-severity operational risk if remote access controls are not properly enforced.",
  "technicalDetails": "The vulnerability stems from improper input validation and sanitization regarding file names and paths supplied by external sources within IBM Db2 Mirror for i. Specifically, the root cause is categorized as an external control of file name or path issue, where user-supplied input is directly utilized in file system operations without adequate verification or restriction against directory traversal techniques.\nDuring the attack flow, a remote and unauthenticated or authenticated attacker leverages network protocols to interact with the vulnerable component of IBM Db2 Mirror for i. By crafting malicious input containing directory traversal sequences (such as dot-dot-slash patterns) or absolute file paths, the attacker can force the application to read, write, or execute files outside of the intended directory structure.\nThe exploitation method relies on the application's failure to restrict file system access to a securely defined sandbox or base directory. When the vulnerable component processes the manipulated file path, it may load and execute arbitrary binaries, scripts, or library files controlled by the attacker. This payload execution occurs with the privileges of the service running the affected IBM Db2 Mirror for i component, which often possesses elevated system privileges.\nThe affected products and versions are explicitly IBM Db2 Mirror for i 7.4, 7.5, and 7.6. Network exposure is present wherever the service is accessible over the network, allowing remote exploitation vectors. Post-exploitation impact includes arbitrary code execution, potential escalation of privileges, unauthorized modification of critical system files, and complete compromise of the database mirroring environment and underlying IBM i operating system."
}
CVE-2026-17184: IBM Db2 Mirror Path Traversal Vulnerability (CRITICAL Severity, CVSS: 9.8) - Sceawere