Executive brief
IBM Db2 is a enterprise database management system used to store and manage critical business data. A vulnerability allows authenticated database administrators to write arbitrary files to the system through a specially crafted request, potentially compromising system integrity and enabling data manipulation or malware deployment.
Technical details
The vulnerability is a path traversal flaw (CWE-22) in IBM Db2 versions 11.5.0-11.5.9 and 12.1.0-12.1.5 that allows authenticated users with DBADM privileges to craft specially crafted requests to write arbitrary files on the filesystem. The attack requires authentication and network access with low complexity, but does not require user interaction. Exploitation permits an attacker to write arbitrary files, which could lead to system compromise, configuration tampering, or introduction of malicious code. Security updates are available for V11.5.9, V12.1.4, and V12.1.5 via the provided links.
Affected products
- IBM Db2 11.5.0 through 11.5.9, 12.1.0 through 12.1.5
Timeline
- 2026-09-10: disclosed
- 2026-09-15: other: Title and summary updated to specify DBADM privilege requirements