CVE-2026-17483: IBM Db2 Mirror for i is affected by multiple vulnerabilities [, , ]
IBM Db2 Mirror for i 7.4, 7.5, and 7.6 IBM i could allow a local attacker to delete historical flight-recorder archives due to improper access control in an SQL procedure.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Db2 Mirror for ito a version that resolves this vulnerability.Fixed in 7.4Patch SJ11151 - Upgrade
Upgrade
IBM Db2 Mirror for ito a version that resolves this vulnerability.Fixed in 7.5Patch SJ11152 - Upgrade
Upgrade
IBM Db2 Mirror for ito a version that resolves this vulnerability.Fixed in 7.6Patch SJ11153 - Upgrade
Upgrade
IBM Db2 Mirror for ito a version that resolves this vulnerability.Patch SJ11193 - Upgrade
Upgrade
IBM Db2 Mirror for ito a version that resolves this vulnerability.Patch SJ11194 - Upgrade
Upgrade
IBM Db2 Mirror for ito a version that resolves this vulnerability.Patch SJ11195 - Upgrade
Upgrade
IBM Db2 Mirror for ito a version that resolves this vulnerability.Patch SJ11205 - Upgrade
Upgrade
IBM Db2 Mirror for ito a version that resolves this vulnerability.Patch SJ11206 - Upgrade
Upgrade
IBM Db2 Mirror for ito a version that resolves this vulnerability.Patch SJ11207 - Compensating control
Address the vulnerability now (per IBM strong recommendation) by installing the listed PTFs for IBM Db2 Mirror for i 7.4, 7.5, and 7.6 so a local attacker cannot delete historical flight-recorder archives via improper access control in an SQL procedure.
Event History
Frequently Asked Questions
Which deployments should be included in triage?
Scope systems running IBM Db2 Mirror for i.
Does the available information indicate a remote attack path?
No remote attack path is described. The issue is identified as exploitable by a local attacker.