Sensitive Information Exposure in IBM Db2 Mirror for i Products
CVE-2026-18104

3.3LOW

Key Information:

Vendor

IBM

Vendor
CVE Published:
24 September 2026

What is CVE-2026-18104?

IBM Db2 Mirror for i versions 7.4, 7.5, and 7.6 are susceptible to vulnerabilities due to the use of the AES Electronic Codebook (ECB) mode for encryption. This mode can potentially allow a local attacker to gain access to sensitive information, posing risks to the data security of the affected systems. It is crucial for users to update their systems and apply recommended patches to mitigate this risk effectively.

Affected Version(s)

Db2 Mirror for i 7.6

Db2 Mirror for i 7.5

Db2 Mirror for i 7.4

References

CVSS V3.1

Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.