CVE-2026-18104: IBM Db2 Mirror for i is vulnerable to obtain sensitive information []
IBM Db2 Mirror for i 7.6, 7.5, and 7.4 could allow a local attacker to obtain sensitive information due to the use of the AES Electronic Codebook (ECB) mode for encryption.
Other sources
IBM i could allow a local attacker to obtain sensitive information due to the use of the AES Electronic Codebook (ECB) mode for encryption.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Db2 Mirror for ito a version that resolves this vulnerability.Patch SJ11538 - Upgrade
Upgrade
IBM Db2 Mirror for ito a version that resolves this vulnerability.Patch SJ11539 - Upgrade
Upgrade
IBM Db2 Mirror for ito a version that resolves this vulnerability.Patch SJ11540
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
An attacker needs local access and low privileges. No user interaction is required.
Which deployments are identified as affected?
IBM Db2 Mirror for i versions 7.6, 7.5, and 7.4 are identified as affected.
What is the expected impact?
The issue may allow disclosure of sensitive information. The provided severity vector indicates no integrity or availability impact.