Executive brief
IBM Db2 is a widely used database system for enterprise data management. A vulnerability causes the database to record login credentials in plain text within diagnostic trace files. A local attacker with system access can read these files to steal database passwords, leading to unauthorized data access and potential breach of sensitive customer or business information.
Technical details
This vulnerability is an instance of CWE-532 (Insertion of Sensitive Information into Log File). The root cause is that IBM Db2 logs plain text database credentials into trace files during operation. An attacker with local system access and standard user privileges can read these diagnostic files and extract authentication credentials. No authentication to the database or user interaction is required for exploitation—only the ability to access the file system locally. The vulnerability affects all supported editions on Linux, UNIX, Windows, and IBM Z Systems. IBM has released security updates available through Fix Central: V11.5.9 (Security Update #87984 or later) and V12.1.4–V12.1.5 (Security Update #86025 or later for V12.1.4, and #88454 or later for V12.1.5).
Affected products
- IBM Db2 11.5.0 through 11.5.9, 12.1.0 through 12.1.5 for Linux, UNIX, Windows, and IBM Z Systems
- IBM Db2 Connect Server 11.5.0 through 11.5.9, 12.1.0 through 12.1.5
Timeline
- 2026-08-12: disclosed: CVE-2026-18097 publicly disclosed
- 2026-08-07: advisory: IBM security bulletin initially published