IBM
IBM DB2 Mirror FOR I: vulnerabilidades y CVE
IBM DB2 Mirror FOR I tiene 28 vulnerabilidades publicadas, 24 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE28
Últimos 12 meses24
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-18104 | Baja (3.3) | 0.06% | — | 24 sept 2026 | IBM Db2 Mirror for i 7.6, 7.5, and 7.4 could allow a local attacker to obtain sensitive information due to the use of the AES Electronic Codebook (ECB) mode for encryption. |
| CVE-2026-17047 | Media (5.4) | 0.12% | — | 14 sept 2026 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to obtain sensitive information due to improper request validation. |
| CVE-2026-17483 | Baja (3.3) | 0.15% | — | 4 sept 2026 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 IBM i could allow a local attacker to delete historical flight-recorder archives due to improper access control in an SQL procedure. |
| CVE-2026-16660 | Media (5.3) | 0.36% | — | 4 sept 2026 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service due to an out-of-bounds read. |
| CVE-2026-18567 | Media (4.7) | 0.07% | — | 4 sept 2026 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a local attacker to obtain information due to a race condition involving a predictable Unix domain socket path in a world-writable directory. |
| CVE-2026-18554 | Alta (7.5) | 0.85% | — | 14 ago 2026 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory. |
| CVE-2026-18178 | Alta (8.1) | 0.54% | — | 14 ago 2026 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to delete arbitrary files due to path traversal. |
| CVE-2026-17227 | Media (6.5) | 0.35% | — | 14 ago 2026 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to improper neutralization of special elements used in an SQL command. |
| CVE-2026-17209 | Media (5.4) | 0.36% | — | 14 ago 2026 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to execute arbitrary scripts due to cross-site scripting. |
| CVE-2026-17186 | Crítica (9.8) | 0.50% | — | 14 ago 2026 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary CL commands due to improper neutralization of special elements in a command. |
| CVE-2026-17184 | Crítica (9.8) | 0.80% | — | 14 ago 2026 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary code due to external control of file name or path. |
| CVE-2026-17182 | Crítica (9.8) | 0.73% | — | 14 ago 2026 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass authentication and obtain or alter sensitive information due to improper validation of request URI path segments. |
| CVE-2026-17181 | Alta (8.6) | 0.55% | — | 14 ago 2026 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write files to arbitrary locations due to path traversal. |
| CVE-2026-17179 | Media (6.5) | 3.1% | — | 14 ago 2026 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to cause a denial of service due to command injection. |
| CVE-2026-17177 | Alta (7.5) | 0.55% | — | 14 ago 2026 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service due to uncontrolled recursion. |
| CVE-2026-17175 | Media (6.5) | 0.52% | — | 14 ago 2026 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication enforcement. |
| CVE-2026-17173 | Media (6.5) | 0.66% | — | 14 ago 2026 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of file paths. |
| CVE-2026-17081 | Alta (7.5) | 0.55% | — | 14 ago 2026 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write arbitrary files due to improper limitation of a pathname to a restricted directory. |
| CVE-2026-17079 | Media (4.3) | 0.32% | — | 14 ago 2026 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to the ability to disable server-side input validation via a request parameter. |
| CVE-2026-16915 | Alta (7.5) | 0.85% | — | 14 ago 2026 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper input validation. |
| CVE-2026-16905 | Media (6.5) | 0.46% | — | 14 ago 2026 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication. |
| CVE-2026-16879 | Alta (8.8) | 0.50% | — | 14 ago 2026 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization using user-supplied input. |
| CVE-2026-16708 | Alta (7.5) | 0.24% | — | 14 ago 2026 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to obtain sensitive information due to external control of system configuration. |
| CVE-2026-16956 | Crítica (9.8) | 0.86% | — | 12 ago 2026 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. |
| CVE-2025-36117 | Media (6.3) | 0.19% | — | 23 jul 2025 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 does not disallow the session id after use which could allow an authenticated user to impersonate another user on the system. |
| CVE-2025-36116 | Media (6.3) | 0.16% | — | 23 jul 2025 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 GUI is affected by cross-site WebSocket hijacking vulnerability. By sending a specially crafted request, an unauthenticated malicious actor could exploit this vulnerability to… |
| CVE-2023-47741 | Media (5.3) | 0.33% | — | 18 dic 2023 | IBM i 7.3, 7.4, 7.5, IBM i Db2 Mirror for i 7.4 and 7.5 web browser clients may leave clear-text passwords in browser memory that can be viewed using common browser tools before the memory is garbage collected. A… |
| CVE-2022-43928 | Media (6.5) | 0.64% | — | 7 abr 2023 | The IBM Toolbox for Java (Db2 Mirror for i 7.4 and 7.5) could allow a user to obtain sensitive information, caused by utilizing a Java string for processing. Since Java strings are immutable, their contents exist in… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de IBM
AIX · 551Websphere Application Server · 519DB2 · 355Vios · 237Sterling B2B Integrator · 205I · 203Rational Quality Manager · 202Qradar Security Information AND Event Manager · 192Infosphere Information Server · 189Maximo Asset Management · 182Rational Doors Next Generation · 153Rational Team Concert · 142