Impact
The vulnerability is a stack‑based buffer overflow in the IXF IMPORT parser, identified as CWE‑121. When an attacker supplies a malicious IXF file during an import operation, the parser can overflow a memory buffer. Based on the description, this could enable arbitrary code execution or cause the Db2 service to crash, potentially compromising confidentiality, integrity, or availability.
Affected Systems
IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.5 are affected. Users of any level within the 11.5 or 12.1 series should verify their exact minor level and apply the corresponding security update (V11.5.9 for 11.5, V12.1.5 or later for 12.1).
Risk and Exploitability
The CVSS score of 8.4 indicates high severity, but the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be local or remote depending on whether an attacker can execute the IXF IMPORT command or provide a malicious file to a user with import privileges. Exploitation may be limited, but the high severity warrants prompt remediation.
OpenCVE Enrichment