Junglewise Threat Intelligence

CVE-2026-10695: IBM Db2 denial of service in federated server

CVE-2026-10695 · Severity: medium · CVSS 6.2 · Published 2026-07-30

Executive brief

IBM Db2 is a database management system used to store and manage large volumes of corporate data. A vulnerability in its federated server component—which allows the database to access data from other sources—could allow an attacker to trigger a denial of service. If exploited, this could cause the database to crash or become unresponsive, disrupting business operations and data availability.

Technical details

IBM Db2 is vulnerable to uncontrolled resource consumption (CWE-400) within the federated server component. The issue occurs specifically when running non-fenced federated queries, which execute in the same address space as the database engine. A local attacker can exploit this to trigger a denial of service condition, impacting system availability. IBM has released a fix in version 12.1.5 (Special Build #87349). As a workaround, administrators can set the federated wrapper to fenced mode using the 'ALTER WRAPPER' command to isolate the process.

Affected products

  • IBM Db2 12.1.0 - 12.1.4

Timeline

  • 2026-07-10: disclosed: Initial publication by IBM
  • 2026-07-30: advisory: NVD publication date

References

Related threats