Description
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow a remote attacker to perform an arbitrary file write due to improper validation of file paths.
Published: 2026-09-14
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote arbitrary file write
Action: Patch Now
AI Analysis

Impact

IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.5 contain an improper validation of file paths that allows a remote attacker to write files arbitrarily on the host. The vulnerability enables the attacker to overwrite or create files on the system, potentially leading to privilege escalation, tampering path traversal flaw (CWE-22).

Affected Systems

The affected products are IBM Db2 database engines from the 11.5 and 12.1 series. Specifically, all levels of release 11.5 up to 11.5.9 and all levels of release 12.1 up to 12.1.5 can be impacted; vendors can apply, V12.1.4, and V12.1.5 respectively.

Risk and Exploitability

The CVSS score of 7.5 indicates a moderate severity; the EPSS score is not provided, so current exploitation likelihood is uncertain, but the vulnerability is listed as not being in the CISA KEV catalog. An attacker would need network access to the JDBC/SQLJ interface and sufficient privileges to use the driver, implying that in environments with exposed database interfaces this flaw could be leveraged to compromise the host. The lack of a publicly disclosed exploit does not negate the risk, as path traversal flaws are often successfully exploited when combined with other weaknesses.

Generated by OpenCVE AI on September 15, 2026 at 07:41 UTC.

Remediation

Vendor Solution

Customers running any vulnerable affected level of an affected Program, V11.5, and V12.1, can download the security update containing the interim fix for this issue from Fix Central. These security updates are available based on the most recent level for each impacted release: V11.5.9, V12.1.4, and V12.1.5. They can be applied to any affected level of the appropriate release to remediate this vulnerability. ReleaseFixed in mod packAPARDownload URLV11.5TBD https://www.ibm.com/support/pages/node/7087189 V12.1TBD https://www.ibm.com/support/pages/node/7267513 Security Update #89304 or later for V12.1.5 available at this link: https://www.ibm.com/support/pages/node/7282633 IBM does not disclose key Db2 functionality nor replication steps for a vulnerability to avoid providing too much information to any potential malicious attacker. IBM does not want to enable a malicious attacker with sufficient knowledge to craft an exploit of the vulnerability.


OpenCVE Recommended Actions

  • Download and apply the security update from IBM Fix Central for the correct release level (V11.5.9 for 11.5 series or V12.1.5 for 12.1 series).
  • Ensure the update is installed on all affected database servers and that the driver configuration limits file path usage to trusted directories.
  • Restrict JDBC/SQLJ network access to trusted internal networks or interfaces to reduce exposure to potential attackers.

Generated by OpenCVE AI on September 15, 2026 at 07:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow a remote attacker to perform an arbitrary file write due to improper validation of file paths.
Title IBM® Data Server driver for JDBC and SQLJ could allow a remote attacker to perform an arbitrary file write due to improper validation of file paths
First Time appeared Ibm
Ibm db2
Weaknesses CWE-22
CPEs cpe:2.3:a:ibm:db2:11.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:11.5.9:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:12.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:12.1.5:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm db2
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-14T19:58:20.474Z

Reserved: 2026-07-16T13:16:40.449Z

Link: CVE-2026-15955

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-14T20:16:39.057

Modified: 2026-09-14T20:16:39.057

Link: CVE-2026-15955

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T07:45:15Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')