CVE-2026-17175
- EPSS 0.6%
- Veröffentlicht 14.08.2026 19:20:16
- Zuletzt bearbeitet 20.08.2026 21:30:10
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication enforcement.
CVE-2026-17173
- EPSS 0.64%
- Veröffentlicht 14.08.2026 19:19:45
- Zuletzt bearbeitet 20.08.2026 21:30:43
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of file paths.
CVE-2026-17081
- EPSS 0.59%
- Veröffentlicht 14.08.2026 19:19:25
- Zuletzt bearbeitet 20.08.2026 21:33:30
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write arbitrary files due to improper limitation of a pathname to a restricted directory.
CVE-2026-17079
- EPSS 0.37%
- Veröffentlicht 14.08.2026 19:19:08
- Zuletzt bearbeitet 20.08.2026 21:36:56
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to the ability to disable server-side input validation via a request parameter.
CVE-2026-16915
- EPSS 0.85%
- Veröffentlicht 14.08.2026 19:18:51
- Zuletzt bearbeitet 20.08.2026 21:37:38
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper input validation.
CVE-2026-16905
- EPSS 0.47%
- Veröffentlicht 14.08.2026 19:18:41
- Zuletzt bearbeitet 20.08.2026 21:38:59
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication.
CVE-2026-16879
- EPSS 0.53%
- Veröffentlicht 14.08.2026 19:18:18
- Zuletzt bearbeitet 20.08.2026 21:39:40
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization using user-supplied input.
CVE-2026-16708
- EPSS 0.41%
- Veröffentlicht 14.08.2026 19:17:21
- Zuletzt bearbeitet 20.08.2026 13:03:39
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to obtain sensitive information due to external control of system configuration.
CVE-2026-16956
- EPSS 1.04%
- Veröffentlicht 12.08.2026 17:30:22
- Zuletzt bearbeitet 13.08.2026 16:47:02
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
CVE-2025-36117
- EPSS 0.19%
- Veröffentlicht 23.07.2025 14:27:08
- Zuletzt bearbeitet 07.08.2025 14:36:42
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 does not disallow the session id after use which could allow an authenticated user to impersonate another user on the system.