VYPR

Db2 Mirror For I

by IBM

CVEs (27)

  • CVE-2026-17227MedAug 14, 2026
    risk 0.35cvss 5.4epss 0.00

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to improper neutralization of special elements used in an SQL command.

  • CVE-2026-16660MedSep 4, 2026
    risk 0.34cvss 5.3epss 0.00

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service due to an out-of-bounds read.

  • CVE-2026-16905MedAug 14, 2026
    risk 0.34cvss 5.3epss 0.00

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication.

  • CVE-2023-47741MedDec 18, 2023
    risk 0.34cvss 5.3epss 0.00

    IBM i 7.3, 7.4, 7.5, IBM i Db2 Mirror for i 7.4 and 7.5 web browser clients may leave clear-text passwords in browser memory that can be viewed using common browser tools before the memory is garbage collected. A malicious actor with access to the victim's PC could exploit this…

  • CVE-2022-43928MedApr 7, 2023
    risk 0.32cvss 4.9epss 0.01

    The IBM Toolbox for Java (Db2 Mirror for i 7.4 and 7.5) could allow a user to obtain sensitive information, caused by utilizing a Java string for processing. Since Java strings are immutable, their contents exist in memory until garbage collected. This means sensitive data…

  • CVE-2026-18567MedSep 4, 2026
    risk 0.29cvss 4.4epss 0.00

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a local attacker to obtain information due to a race condition involving a predictable Unix domain socket path in a world-writable directory.

  • CVE-2026-17483MedSep 4, 2026
    risk 0.28cvss 4.3epss 0.00

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 IBM i could allow a local attacker to delete historical flight-recorder archives due to improper access control in an SQL procedure.

Page 2 of 2