Impact
The vulnerability resides in IBM Db2 Genius Hub 1.1 through 1.1.2 and IBM Agentics 1.0 and results from the use of a function that is considered potentially dangerous without adequate safeguards. This leads to the possibility of arbitrary code execution or the exposure of sensitive information, as the function could be invoked with malicious input. The weakness is classified as CWE‑676, indicating improper use of a function that may carry unintended side effects.
Affected Systems
Systems affected include IBM Agentics version 1.0 and IBM Db2 Genius Hub versions 1.1, 1.1.1, and 1.1.2. These products are delivered via IBM’s business analytics suites and are typically installed on enterprise servers handling potentially sensitive data. Any environment deploying these specific releases is subject to the vulnerability until a fix is applied.
Risk and Exploitability
With a CVSS score of 4.3, the vulnerability presents a moderate risk level. The EPSS score of less than 1% suggests very low exploitation probability at present, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is inferred to be application‑level or local, because the description does not specify remote network exploitation but indicates that the dangerous function can be triggered with suitable input. An attacker with sufficient access to influence the function’s parameters could potentially execute code or read protected data.
OpenCVE Enrichment