Executive brief
IBM Db2, a widely used enterprise database management system, is affected by a vulnerability that could allow an authorized user to view sensitive information they should not have access to. By querying specific monitoring and event tables, a user with local access to the system can retrieve internal data. This could lead to the exposure of confidential business information or system metadata, though it does not allow the attacker to modify data or crash the service.
Technical details
An information disclosure vulnerability exists in IBM Db2 for Linux, UNIX, and Windows (including Db2 Connect Server) versions 11.5 and 12.1. The flaw is categorized as CWE-538, where sensitive information is inserted into monitoring and event tables that are accessible to authenticated users. An attacker with local access and low privileges can exploit this by querying these tables to extract sensitive data. The vulnerability has a CVSS base score of 5.5, reflecting high confidentiality impact but no impact on integrity or availability. IBM has released special builds (interim fixes) for versions 11.5.9 and 12.1.4 to remediate the issue.
Affected products
- IBM Db2 for Linux, UNIX and Windows 11.5.0 - 11.5.9, 12.1.0 - 12.1.4
- IBM Db2 Connect Server 11.5.0 - 11.5.9, 12.1.0 - 12.1.4
Timeline
- 2026-06-23: disclosed: Initial publication by IBM
- 2026-06-25: advisory: Updated advisory to specify all platforms are impacted
- 2026-06-30: other: NVD publication date