Vulnerability
Published 2026-09-14
Verified 2026-09-19

IBM Db2 Mirror for i web GUI: Silent Signal pre-auth chain to Liberty JSP RCE and QSECOFR

Silent Signal (14 September 2026) documents a pre-authentication vulnerability chain in the IBM Db2 Mirror for i web interface (Db2MirrorServlet on the IBM i administrative Liberty instance; lab IBM i V7R5, GUI WAR build timestamp late 2025). The write-up describes how authentication/validation filters can be confused, enabling unauthenticated reach into powerful admin features (arbitrary file read via log/trace viewers, attacker-influenced writes into an expanded WAR path that becomes JSP execution in Liberty, then a native helper crossing to QSECOFR on the local IBM i system). No CVE identifier is assigned in the post; the author withholds exploit/JSP payload bodies and frames the piece as vulnerability mechanics plus hardening guidance. Confirm IBM PSIRT/bulletin status for your Db2 Mirror for i / IBM i web stack build before declaring patched. Primary: Silent Signal; no separate vendor bulletin URL confirmed at desk time.

Product
IBM Db2 Mirror for i (web GUI / Liberty on IBM i)
Versions
Tested on IBM i V7R5 with a late-2025 Db2 Mirror GUI WAR; exact fixed PTF/build not stated in the write-up — verify against IBM security notices for your release
Exploited in Australia?
unknown
Patch to
IBM i admins: restrict Db2 Mirror / admin Liberty exposure; apply current IBM security PTFs for Db2 Mirror for i and related web stack; review auth filters and expanded-WAR write paths per Silent Signal guidance

Primary: Silent Signal — Db2 Mirror for i pre-auth RCE chain (14 Sep 2026) · Talkback index (wire discovery 15 Sep 2026 desk pass)

vulnerabilities identity network