CVE-2026-18104
- EPSS 0.06%
- Veröffentlicht 24.09.2026 14:17:12
- Zuletzt bearbeitet 29.09.2026 14:00:07
IBM Db2 Mirror for i 7.6, 7.5, and 7.4 could allow a local attacker to obtain sensitive information due to the use of the AES Electronic Codebook (ECB) mode for encryption.
CVE-2026-17047
- EPSS 0.12%
- Veröffentlicht 14.09.2026 19:42:16
- Zuletzt bearbeitet 16.09.2026 19:22:22
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to obtain sensitive information due to improper request validation.
CVE-2026-16660
- EPSS 0.36%
- Veröffentlicht 04.09.2026 16:42:34
- Zuletzt bearbeitet 10.09.2026 21:17:19
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service due to an out-of-bounds read.
CVE-2026-17483
- EPSS 0.23%
- Veröffentlicht 04.09.2026 16:31:14
- Zuletzt bearbeitet 10.09.2026 16:17:08
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 IBM i could allow a local attacker to delete historical flight-recorder archives due to improper access control in an SQL procedure.
CVE-2026-18567
- EPSS 0.08%
- Veröffentlicht 04.09.2026 16:17:20
- Zuletzt bearbeitet 08.09.2026 21:43:59
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a local attacker to obtain information due to a race condition involving a predictable Unix domain socket path in a world-writable directory.
CVE-2026-18554
- EPSS 0.85%
- Veröffentlicht 14.08.2026 19:23:50
- Zuletzt bearbeitet 21.08.2026 12:44:16
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory.
CVE-2026-18178
- EPSS 0.44%
- Veröffentlicht 14.08.2026 19:23:30
- Zuletzt bearbeitet 21.08.2026 12:46:41
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to delete arbitrary files due to path traversal.
CVE-2026-17227
- EPSS 0.33%
- Veröffentlicht 14.08.2026 19:23:15
- Zuletzt bearbeitet 21.08.2026 12:56:55
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to improper neutralization of special elements used in an SQL command.
CVE-2026-17209
- EPSS 0.43%
- Veröffentlicht 14.08.2026 19:22:58
- Zuletzt bearbeitet 21.08.2026 13:04:48
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to execute arbitrary scripts due to cross-site scripting.
CVE-2026-17186
- EPSS 0.47%
- Veröffentlicht 14.08.2026 19:22:46
- Zuletzt bearbeitet 21.08.2026 13:09:10
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary CL commands due to improper neutralization of special elements in a command.