Researchers disclosed a pre-authentication exploit chain in the IBM Db2 Mirror for i GUI WAR running on an IBM i Liberty administrative server. A semicolon path parameter can cause AuthFilter to miss the Db2MirrorServlet route, bypassing session authentication and other checks; an unauthenticated session parameter can then disable request validation. The exposed LogAction.getLogFileContent function enables arbitrary file reads, while attacker-controlled IBM Toolbox trace-file settings provide a write primitive capable of creating a JSP in the expanded WAR directory.
The malicious JSP executes in the Liberty JVM, giving an unauthenticated attacker server-side Java execution. In a tested IBM i V7R5 environment, researchers used the QLWIUTIL3-backed NativeMethods.doMethod helper to make a local Db2 connection identify as QSECOFR, IBM i's highest-privilege authority, potentially converting the remote compromise into full system-level control. The available reporting does not identify a CVE, affected-version range, patch, or confirmed exploitation in the wild.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
A write-up disclosed an authentication-bypass and validation-bypass chain in the IBM Db2 Mirror for i GUI that enables unauthenticated file reads and can create and execute a JSP in the Liberty server context. In a tested IBM i V7R5 environment, the resulting Java execution could invoke a native helper that caused a local Db2 connection to run as QSECOFR, potentially escalating to highest-authority access.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.