Executive brief
IBM Db2, a widely used enterprise database management system, is affected by a critical security flaw in its communication protocol. An unauthorized attacker can exploit this vulnerability to execute malicious commands on the database server without needing a username or password. This could lead to a total compromise of the database, including the theft of sensitive customer data, service disruption, or the installation of ransomware.
Technical details
IBM Db2 contains a code injection vulnerability (CWE-94) within its implementation of the Distributed Relational Database Architecture (DRDA) protocol. The flaw exists in the pre-authentication handshake process, where improper validation of initial connection requests allows for remote code execution. An unauthenticated attacker can trigger this vulnerability over the network by sending a specially crafted DRDA handshake packet. Successful exploitation grants the attacker the ability to execute arbitrary code with the privileges of the Db2 instance owner. IBM has released special builds for versions 11.5.9 and 12.1.4 to remediate this issue.
Affected products
- IBM Db2 11.5.0 - 11.5.9, 12.1.0 - 12.1.4
Timeline
- 2026-06-23: disclosed: Initial publication by IBM
- 2026-06-23: patched: Special builds released for V11.5 and V12.1
- 2026-06-30: advisory: NVD publication date