Description
IBM Db2 12.1.0 through 12.1.4 federated server is vulnerable to a denial of service when running non fenced federated queries.
Published: 2026-07-30
Score: 6.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

IBM Db2 versions 12.1.0 through 12.1.4 have a vulnerability that causes a denial of service when executing non‑fenced federated queries. The weakness allows an attacker with the ability to run these queries to trigger a crash of the Db2 federated server, resulting in an availability outage. The flaw matches CWE‑400 for input or resource exhaustion.

Affected Systems

The affected product is IBM Db2 for the 12.1 release line, including all sub‑releases from 12.1.0 up to 12.1.4. Any deployment that includes a federated wrapper without fenced mode is susceptible until patched.

Risk and Exploitability

The CVSS score of 6.2 indicates a moderate severity. The EPSS score of < 1% suggests a very low probability of exploitation; the vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation to date. The likely attack vector is any user or application capable of issuing federated queries; through such a query the attacker can trigger a crash and disrupt database service availability. While no remote code execution is involved, the impact on business continuity can be significant.

Generated by OpenCVE AI on August 3, 2026 at 10:39 UTC.

Remediation

Vendor Solution

Customers running any vulnerable modpack level of an affected Program, V12.1, can download the special build containing the interim fix for this issue from Fix Central. These special builds are available based on the most recent level for each impacted release: V12.1.4. They can be applied to any affected level of the appropriate release to remediate this vulnerability. ReleaseFixed in mod packAPARDownload URL V12.1 v12.1.5 https://www.ibm.com/support/pages/node/7267513 IBM does not disclose key Db2 functionality nor replication steps for a vulnerability to avoid providing too much information to any potential malicious attacker. IBM does not want to enable a malicious attacker with sufficient knowledge to craft an exploit of the vulnerability.


Vendor Workaround

Set the federated wrapper to fenced mode using ALTER WRAPPER <wrapper_name> OPTIONS (SET DB2_FENCED 'Y')


OpenCVE Recommended Actions

  • Download and install the special build (interim fix) from IBM Fix Central for the affected Db2 12.1 version.
  • If the patch cannot be applied immediately, configure the federated wrapper to fenced mode using ALTER WRAPPER <wrapper_name> OPTIONS (SET DB2_FENCED 'Y') to block non‑fenced queries.
  • Consider upgrading to a newer Db2 release that eliminates this defect, or monitor system availability closely after remediation.

Generated by OpenCVE AI on August 3, 2026 at 10:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 01 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Description IBM Db2 12.1.0 through 12.1.4 federated server is vulnerable to a denial of service when running non fenced federated queries.
Title IBM® Db2® is vulnerable to a denial of service when running non fenced federated queries
First Time appeared Ibm
Ibm db2
Weaknesses CWE-400
CPEs cpe:2.3:a:ibm:db2:12.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:12.1.4:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm db2
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-07-30T18:07:42.667Z

Reserved: 2026-06-02T16:01:12.558Z

Link: CVE-2026-10695

cve-icon Vulnrichment

Updated: 2026-07-30T18:04:17.790Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T19:17:01.830

Modified: 2026-08-05T20:30:07.583

Link: CVE-2026-10695

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T10:45:03Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption