Executive brief
IBM Db2 is a widely-used relational database system deployed across enterprises. An authenticated attacker can trigger uncontrolled resource consumption on vulnerable Db2 servers, causing them to become unresponsive and disrupting business operations and data access. The vulnerability requires valid database credentials but can be exploited remotely over the network.
Technical details
This vulnerability is a denial of service flaw caused by uncontrolled resource consumption (CWE-400) in IBM Db2 versions 11.5.0–11.5.9 and 12.1.0–12.1.5 on Linux, UNIX, and Windows platforms (including Db2 Connect Server). Attack requires network access and valid database authentication (PR:L in CVSS vector), but no user interaction. An authenticated attacker can send specially crafted requests that exhaust server resources, rendering the database unavailable. Security updates are available for v11.5.9, v12.1.4, and v12.1.5; IBM has not disclosed exploit details to prevent misuse.
Affected products
- IBM Db2 11.5.0 through 11.5.9, 12.1.0 through 12.1.5
- IBM Db2 Connect Server 11.5.0 through 11.5.9, 12.1.0 through 12.1.5
Timeline
- 2026-09-14: disclosed