Executive brief
IBM Db2 is a widely used enterprise database management system. A security flaw in its JDBC data driver allows an attacker with local access to execute unauthorized commands on the system if they can control the database connection string. This could lead to a full system compromise, data theft, or disruption of database services.
Technical details
A code injection vulnerability (CWE-94) exists in the IBM Data Server Driver for JDBC and SQLJ used by IBM Db2. The flaw is triggered when an application allows untrusted user input to influence the JDBC connection URL. An attacker with local access and low privileges can exploit this to execute arbitrary code with the permissions of the application using the driver. The vulnerability affects Db2 Client versions 11.5 (up to 11.5.9) and 12.1 (up to 12.1.4) across all platforms including Linux, AIX, and Windows. IBM has released special builds for V11.5.9 and V12.1.4 to remediate the issue.
Affected products
- IBM Db2 Client 11.5.0 - 11.5.9, 12.1.0 - 12.1.4
- IBM Data Server Driver for JDBC and SQLJ 11.5.0 - 11.5.9, 12.1.0 - 12.1.4
Timeline
- 2026-07-10: disclosed: Initial publication by IBM
- 2026-07-17: advisory: NVD publication date