IBM Db2 Mirror For I
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in IBM Db2 Mirror For I.
By the Year
In 2026 there have been 19 vulnerabilities in IBM Db2 Mirror For I with an average score of 7.8 out of ten. Last year, in 2025 Db2 Mirror For I had 2 security vulnerabilities published. That is, 17 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 1.47.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 19 | 7.77 |
| 2025 | 2 | 6.30 |
| 2024 | 0 | 0.00 |
| 2023 | 2 | 5.90 |
It may take a day or so for new Db2 Mirror For I vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent IBM Db2 Mirror For I Security Vulnerabilities
IBM Db2 Mirror for i 7.47.6 Pathname Lmt Bypass Allows Info Disclosure
CVE-2026-18554
7.5 - High
- August 14, 2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory.
Directory traversal
IBM Db2 Mirror for i 7.47.6 | Path Traversal => Remote File Delete
CVE-2026-18178
5.4 - Medium
- August 14, 2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to delete arbitrary files due to path traversal.
Directory traversal
Remote Auth Bypass in IBM Db2 Mirror for i (7.4-7.6) via SQL Injection
CVE-2026-17227
5.4 - Medium
- August 14, 2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to improper neutralization of special elements used in an SQL command.
SQL Injection
IBM Db2 Mirror for i 7.4-7.6 XSS Remote Auth Exec
CVE-2026-17209
6.3 - Medium
- August 14, 2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to execute arbitrary scripts due to cross-site scripting.
XSS
IBM Db2 Mirror for i 7.6 Remote CL Cmd Exec via Improper Escaping
CVE-2026-17186
9.9 - Critical
- August 14, 2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary CL commands due to improper neutralization of special elements in a command.
Shell injection
IBM Db2 Mirror for i 7.4-7.6 RCE via External File Path
CVE-2026-17184
9.8 - Critical
- August 14, 2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary code due to external control of file name or path.
External Control of File Name or Path
IBM Db2 Mirror for i Auth Bypass via Improper URI Path Validation 7.47.6
CVE-2026-17182
9.8 - Critical
- August 14, 2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass authentication and obtain or alter sensitive information due to improper validation of request URI path segments.
authentification
IBM Db2 Mirror for i 7.47.6 Path Traversal Remote File Write
CVE-2026-17181
9.3 - Critical
- August 14, 2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write files to arbitrary locations due to path traversal.
Directory traversal
IBM Db2 Mirror for i 7.4-7.6 Remote Cmd Inject DoS
CVE-2026-17179
8.5 - High
- August 14, 2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to cause a denial of service due to command injection.
Shell injection
DoS via Uncontrolled Recursion in IBM DB2 Mirror for i 7.4-7.6
CVE-2026-17177
7.5 - High
- August 14, 2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service due to uncontrolled recursion.
Stack Exhaustion
IBM Db2 Mirror for i, v7.4-7.6 Improper Auth Enforcement Remote Info Disclosure
CVE-2026-17175
7.5 - High
- August 14, 2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication enforcement.
authentification
IBM Db2 Mirror for i 7.47.6 Path Traversal Remote Auth
CVE-2026-17173
6.5 - Medium
- August 14, 2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of file paths.
Directory traversal
IBM Db2 Mirror i 7.[46] Remote File Write via Unrestricted Path
CVE-2026-17081
8.2 - High
- August 14, 2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write arbitrary files due to improper limitation of a pathname to a restricted directory.
Directory traversal
IBM Db2 Mirror for i <7.7: Authenticated Remote Bypass via Param
CVE-2026-17079
6.3 - Medium
- August 14, 2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to the ability to disable server-side input validation via a request parameter.
Protection Mechanism Failure
Remote Authenticated Info Disclosure in IBM Db2 Mirror for i 7.4-7.6
CVE-2026-16915
7.5 - High
- August 14, 2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper input validation.
Directory traversal
IBM Db2 Mirror for i 7.47.6 Remote Auth Improper Auth Disclosure
CVE-2026-16905
5.3 - Medium
- August 14, 2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication.
authentification
IBM Db2 Mirror for i 7.47.6 Remote Auth Bypass via Improper Authorization
CVE-2026-16879
8.8 - High
- August 14, 2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization using user-supplied input.
AuthZ
IBM Db2 Mirror for i 7.4-7.6 Remote Config Control for Data Leakage
CVE-2026-16708
8.3 - High
- August 14, 2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to obtain sensitive information due to external control of system configuration.
External Control of System or Configuration Setting
IBM Db2 Mirror for i 7.4-7.6: RCE via OS Cmd Injection
CVE-2026-16956
9.8 - Critical
- August 12, 2026
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
Shell injection
IBM Db2 Mirror for i GUI WebSocket Hijacking, before 7.7
CVE-2025-36116
6.3 - Medium
- July 23, 2025
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 GUI is affected by cross-site WebSocket hijacking vulnerability. By sending a specially crafted request, an unauthenticated malicious actor could exploit this vulnerability to sniff an existing WebSocket connection to then remotely perform operations that the user is not allowed to perform.
1385
Session ID Reuse in IBM Db2 Mirror for i 7.4-7.6 -> User Impersonation
CVE-2025-36117
6.3 - Medium
- July 23, 2025
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 does not disallow the session id after use which could allow an authenticated user to impersonate another user on the system.
Session Fixation
IBM i & Db2 Mirror Browser Leak Clear-Text Passwords in Memory
CVE-2023-47741
5.3 - Medium
- December 18, 2023
IBM i 7.3, 7.4, 7.5, IBM i Db2 Mirror for i 7.4 and 7.5 web browser clients may leave clear-text passwords in browser memory that can be viewed using common browser tools before the memory is garbage collected. A malicious actor with access to the victim's PC could exploit this vulnerability to gain access to the IBM i operating system. IBM X-Force ID: 272532.
Insufficiently Protected Credentials
IBM Toolbox for Java (Db2 Mirror for i 7.4/7.5) Memory Leak of Sensitive Data
CVE-2022-43928
6.5 - Medium
- April 07, 2023
The IBM Toolbox for Java (Db2 Mirror for i 7.4 and 7.5) could allow a user to obtain sensitive information, caused by utilizing a Java string for processing. Since Java strings are immutable, their contents exist in memory until garbage collected. This means sensitive data could be visible in memory over an indefinite amount of time. IBM has addressed this issue by reducing the amount of time the sensitive data is visible in memory. IBM X-Force ID: 241675.
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for IBM Db2 Mirror For I or by IBM? Click the Watch button to subscribe.