VYPR

Db2 Mirror For I

by IBM

CVEs (27)

  • CVE-2026-17186CriAug 14, 2026
    risk 0.64cvss 9.9epss 0.00

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary CL commands due to improper neutralization of special elements in a command.

  • CVE-2026-17184CriAug 14, 2026
    risk 0.64cvss 9.8epss 0.01

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary code due to external control of file name or path.

  • CVE-2026-17182CriAug 14, 2026
    risk 0.64cvss 9.8epss 0.00

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass authentication and obtain or alter sensitive information due to improper validation of request URI path segments.

  • CVE-2026-16956CriAug 12, 2026
    risk 0.64cvss 9.8epss 0.01

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

  • CVE-2026-17181CriAug 14, 2026
    risk 0.60cvss 9.3epss 0.00

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write files to arbitrary locations due to path traversal.

  • CVE-2026-16879HigAug 14, 2026
    risk 0.57cvss 8.8epss 0.00

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization using user-supplied input.

  • CVE-2026-17179HigAug 14, 2026
    risk 0.55cvss 8.5epss 0.01

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to cause a denial of service due to command injection.

  • CVE-2026-16708HigAug 14, 2026
    risk 0.54cvss 8.3epss 0.00

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to obtain sensitive information due to external control of system configuration.

  • CVE-2026-17081HigAug 14, 2026
    risk 0.53cvss 8.2epss 0.00

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write arbitrary files due to improper limitation of a pathname to a restricted directory.

  • CVE-2026-18554HigAug 14, 2026
    risk 0.49cvss 7.5epss 0.01

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory.

  • CVE-2026-17177HigAug 14, 2026
    risk 0.49cvss 7.5epss 0.00

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service due to uncontrolled recursion.

  • CVE-2026-17175HigAug 14, 2026
    risk 0.49cvss 7.5epss 0.00

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication enforcement.

  • CVE-2026-16915HigAug 14, 2026
    risk 0.49cvss 7.5epss 0.01

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper input validation.

  • CVE-2026-17173MedAug 14, 2026
    risk 0.42cvss 6.5epss 0.00

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of file paths.

  • CVE-2026-17209MedAug 14, 2026
    risk 0.41cvss 6.3epss 0.00

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to execute arbitrary scripts due to cross-site scripting.

  • CVE-2026-17079MedAug 14, 2026
    risk 0.41cvss 6.3epss 0.00

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to the ability to disable server-side input validation via a request parameter.

  • CVE-2025-36117MedJul 23, 2025
    risk 0.41cvss 6.3epss 0.00

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 does not disallow the session id after use which could allow an authenticated user to impersonate another user on the system.

  • CVE-2025-36116MedJul 23, 2025
    risk 0.41cvss 6.3epss 0.00

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 GUI is affected by cross-site WebSocket hijacking vulnerability. By sending a specially crafted request, an unauthenticated malicious actor could exploit this vulnerability to sniff an existing WebSocket connection to then remotely perform…

  • CVE-2026-17047MedSep 14, 2026
    risk 0.35cvss 5.4epss 0.00

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to obtain sensitive information due to improper request validation.

  • CVE-2026-18178MedAug 14, 2026
    risk 0.35cvss 5.4epss 0.00

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to delete arbitrary files due to path traversal.

Page 1 of 2