Executive brief
IBM Db2 and Db2 Warehouse on Cloud Pak for Data are enterprise-grade database and analytics platforms. A vulnerability in these systems could allow a logged-in user to bypass security checks and modify data by intercepting network traffic. This could lead to unauthorized changes to sensitive business information or database records.
Technical details
The vulnerability is classified as an authentication bypass by capture-replay (CWE-294). It affects IBM Db2 and Db2 Warehouse on Cloud Pak for Data versions 4.8 through 5.3. An authenticated attacker with network access could potentially bypass client-side validation mechanisms. By utilizing man-in-the-middle (MitM) techniques, the attacker can manipulate input data sent to the server. Exploitation requires a high complexity (AC:H) and existing low-level privileges (PR:L), but can result in a high impact on data integrity. IBM has released security bulletins to address these vulnerabilities in the affected Cloud Pak for Data components.
Affected products
- IBM Db2 on Cloud Pak for Data 4.8, 5.0, 5.1, 5.2, 5.3
- IBM Db2 Warehouse on Cloud Pak for Data 4.8, 5.0, 5.1, 5.2, 5.3
Timeline
- 2026-06-22: disclosed: Initial publication date
- 2026-06-22: advisory