VYPR
patchPublished Sep 4, 2026· Updated Sep 8, 2026· 1 source

IBM Db2 Mirror for i: Three Medium-Severity Flaws Disclosed Together

Key findings • Three medium-severity vulnerabilities disclosed together for IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6. • CVE-2026-17483: Local attacker can delete historical flight-reco…

Key findings

  • Three medium-severity vulnerabilities disclosed together for IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6.
  • CVE-2026-17483: Local attacker can delete historical flight-recorder archives via SQL procedure flaws.
  • CVE-2026-16660: Remote attacker can cause denial of service due to an out-of-bounds read.
  • CVE-2026-18567: Local attacker can obtain information via a race condition in a world-writable directory.

On September 4, 2026, IBM disclosed three medium-severity vulnerabilities affecting Db2 Mirror for i versions 7.4, 7.5, and 7.6. The vulnerabilities, disclosed within a one-hour window, include issues related to improper access control, denial of service, and information disclosure.

One vulnerability, CVE-2026-17483, allows a local attacker to delete historical flight-recorder archives. This is due to improper access control within an SQL procedure. The CVSSv3 score for this vulnerability is 4.3.

Another vulnerability, CVE-2026-16660, could permit a remote attacker to cause a denial of service. This is a result of an out-of-bounds read vulnerability, with a CVSSv3 score of 5.3.

The third vulnerability, CVE-2026-18567, enables a local attacker to obtain sensitive information. This is facilitated by a race condition involving a predictable Unix domain socket path located in a world-writable directory. This vulnerability has a CVSSv3 score of 4.4.

All three vulnerabilities affect Db2 Mirror for i versions 7.4, 7.5, and 7.6. IBM has not released specific patch information in the provided details, but users are advised to consult IBM's official advisories for the latest updates and mitigation strategies.

These vulnerabilities highlight potential risks for users of IBM Db2 Mirror for i, particularly concerning data integrity, service availability, and information confidentiality. Users should ensure their systems are updated to the latest available versions and review their security configurations to mitigate these risks.

Synthesized by Vypr AI