Executive brief
IBM Db2 is a database management system used by organizations to store and manage critical business data. A vulnerability has been identified that allows an authorized user to crash the database service by running a specifically crafted data query. This could lead to a service outage, preventing applications and employees from accessing necessary information until the system is recovered.
Technical details
IBM Db2 (including Db2 Connect Server) is vulnerable to a denial of service (DoS) due to improper input validation (CWE-20/CWE-1284) within its data query logic. An authenticated attacker with network access can trigger this vulnerability by submitting a specially crafted SQL query containing multiple subqueries. This causes the database engine to fail or hang, resulting in a denial of service condition. The issue affects versions 11.5 and 12.1 on Linux, UNIX, and Windows platforms. IBM has released special builds (interim fixes) for versions 11.5.9 and 12.1.4 to remediate the flaw.
Affected products
- IBM Db2 for Linux, UNIX and Windows 11.5.0 - 11.5.9, 12.1.0 - 12.1.4
- IBM Db2 Connect Server 11.5.0 - 11.5.9, 12.1.0 - 12.1.4
Timeline
- 2026-04-15: disclosed: Initial publication by IBM
- 2026-04-30: advisory: NVD publication date