Vulnerabilities
Vulnerable Software
Ibm:  >> Db2 Mirror For I  >> 7.5  Security Vulnerabilities
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service due to uncontrolled recursion.
CVSS Score
7.5
EPSS Score
0.003
Published
2026-08-14
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to cause a denial of service due to command injection.
CVSS Score
8.5
EPSS Score
0.012
Published
2026-08-14
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write files to arbitrary locations due to path traversal.
CVSS Score
9.3
EPSS Score
0.004
Published
2026-08-14
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass authentication and obtain or alter sensitive information due to improper validation of request URI path segments.
CVSS Score
9.8
EPSS Score
0.004
Published
2026-08-14
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to obtain sensitive information due to external control of system configuration.
CVSS Score
8.3
EPSS Score
0.002
Published
2026-08-14
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization using user-supplied input.
CVSS Score
8.8
EPSS Score
0.003
Published
2026-08-14
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication.
CVSS Score
5.3
EPSS Score
0.003
Published
2026-08-14
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper input validation.
CVSS Score
7.5
EPSS Score
0.006
Published
2026-08-14
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
CVSS Score
9.8
EPSS Score
0.01
Published
2026-08-12
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 GUI is affected by cross-site WebSocket hijacking vulnerability. By sending a specially crafted request, an unauthenticated malicious actor could exploit this vulnerability to sniff an existing WebSocket connection to then remotely perform operations that the user is not allowed to perform.
CVSS Score
6.3
EPSS Score
0.002
Published
2025-07-23


Contact Us

Shodan ® - All rights reserved