CVE-2026-17184 PUBLISHED

IBM Db2 Mirror for i is affected by multiple vulnerabilities

Assigner: ibm
Reserved: 24.07.2026 Published: 14.08.2026 Updated: 14.08.2026

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary code due to external control of file name or path.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8

Product Status

Vendor IBM
Product Db2 Mirror for i
Versions
  • Version 7.4 is affected
  • Version 7.5 is affected
  • Version 7.6 is affected

Solutions

IBM strongly recommends addressing the vulnerability now.

IBM i Release

5770-DBM PTF Numbers

PTF Download Link

7.4

SJ10947

https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10947

7.5

SJ10961

https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10961

7.6

SJ10948

https://www.ibm.com/mysupport/s/fix-information?legacy=SJ10948

https://www.ibm.com/support/fixcentral

References

Problem Types

  • CWE-73 External Control of File Name or Path CWE