Impact
IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.4 allow an attacker to execute arbitrary code before authentication by manipulating the DRDA handshake. The vulnerability arises from improper validation of incoming DRDA messages. This weakness is classified as CWE‑94, an instance of code injection through untrusted input.
Affected Systems
All IBM Db2 databases deployed at levels 11.5.0 up to 11.5.9 and 12.1.0 up to 12.1.4 are potentially affected. The most recent supported releases that can remediate the issue are 11.5.9 and 12.1.4. Administrators should identify deployments matching these version ranges to assess risk.
Risk and Exploitability
The CVSS score of 9.8 indicates high severity. No EPSS score available; the exploitation probability is unknown. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the likely attack vector is remote over the network via a malicious DRDA client session, where an attacker can deliver a crafted handshake payload to gain code execution.
OpenCVE Enrichment