Executive brief
IBM Db2 is a database management system used to store and manage large volumes of corporate data. A security flaw in certain versions allows an authenticated user to bypass authorization checks when uploading data to remote storage. This could allow an attacker to modify or overwrite files in remote object storage locations that they should not have access to, potentially compromising data integrity.
Technical details
IBM Db2 versions 12.1.0 through 12.1.4 are vulnerable to an improper authorization flaw (CWE-285). The vulnerability exists when performing uploads to remote object storage paths (using the DB2REMOTE protocol) via a 'special query.' An authenticated attacker with network access can exploit this to bypass intended access controls and perform unauthorized write operations to remote storage. The issue specifically affects Linux and UNIX deployments; Windows installations are not affected. IBM has released special builds for version 12.1.4 to address this issue (APAR DT468154).
Affected products
- IBM Db2 for Linux, UNIX and Windows 12.1.0 - 12.1.4
Timeline
- 2026-05-21: advisory: Initial publication by IBM
- 2026-05-27: disclosed: NVD publication date