Executive brief
IBM Db2 is a database management system used by enterprises to store and manage critical business data. A vulnerability in certain Db2 commands allows non-privileged database users to bypass authorization checks and modify sensitive database catalog data, potentially compromising data integrity and enabling unauthorized changes to the database structure.
Technical details
This is an improper authorization vulnerability (CWE-602: Client-Side Enforcement of Server-Side Security) affecting certain Db2 commands. The vulnerability allows a non-privileged user to bypass authority checks and modify database catalog data. Attack requires network access and valid database credentials (PR:L). The vulnerability has been patched via security updates available for affected versions; fixes include interim patches for V11.5.9, V12.1.4, and V12.1.5. No exploitation in the wild has been reported.
Affected products
- IBM Db2 11.5.0 through 11.5.9, 12.1.0 through 12.1.5
Timeline
- 2026-08-12: disclosed