Executive brief
IBM Db2 is a relational database server used by enterprises to store and manage critical business data. A DBADM-privileged attacker (typically a database administrator) can exploit this vulnerability to disable specific database functionality and cause service unavailability under certain conditions. This impacts business operations and data availability, though it requires administrative privileges to execute.
Technical details
The vulnerability is a privilege management flaw (CWE-269) affecting Db2 versions 11.5.0–11.5.9 and 12.1.0–12.1.5. A user with DBADM (database administrator) authority can disable specific Db2 server functionality under certain conditions, leading to denial of service. The attack requires network access and valid DBADM credentials; no user interaction is needed. IBM has not disclosed the specific functionality affected or detailed attack steps to prevent weaponization. Patches are available via IBM security updates for V11.5.9, V12.1.4, and V12.1.5.
Affected products
- IBM Db2 11.5.0 through 11.5.9, 12.1.0 through 12.1.5
Timeline
- 2026-09-10: disclosed: Initial publication of security bulletin
- 2026-09-16: advisory: Title and summary updated to specify DBADM privilege requirements