Impact
IBM Db2 11.5.0 through 11.5.9 and 12.1.0 through 12.1.5 contain a flaw that allows a specially crafted query to bypass normal privilege checks and elevate a user’s privileges within the database. The weakness is a classic privilege escalation flaw identified as CWE‑285. An attacker who can submit the crafted query can gain higher privileges than originally assigned, potentially enabling them to perform any operation permitted to the elevated user.
Affected Systems
All installations of IBM Db2 at release levels 11.5.0 to 11.5.9 and 12.1.0 to 12.1.5 are affected. Customers using any of these versions should assess whether the instance is accessible to authenticated users that could submit a crafted query.
Risk and Exploitability
The CVSS score of 8.2 indicates a high severity risk. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, so current exploitation evidence is not known. The likely attack vector is an authenticated database user able to submit the crafted query; no privileges beyond the current user role are required, making the issue potentially dangerous. Exfiltration or modification of data would depend on the privileges gained after escalation.
OpenCVE Enrichment