Impact
IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.5 contain an improper validation of file paths that allows a remote attacker to write files arbitrarily on the host. The vulnerability enables the attacker to overwrite or create files on the system, potentially leading to privilege escalation, tampering path traversal flaw (CWE-22).
Affected Systems
The affected products are IBM Db2 database engines from the 11.5 and 12.1 series. Specifically, all levels of release 11.5 up to 11.5.9 and all levels of release 12.1 up to 12.1.5 can be impacted; vendors can apply, V12.1.4, and V12.1.5 respectively.
Risk and Exploitability
The CVSS score of 7.5 indicates a moderate severity; the EPSS score is not provided, so current exploitation likelihood is uncertain, but the vulnerability is listed as not being in the CISA KEV catalog. An attacker would need network access to the JDBC/SQLJ interface and sufficient privileges to use the driver, implying that in environments with exposed database interfaces this flaw could be leveraged to compromise the host. The lack of a publicly disclosed exploit does not negate the risk, as path traversal flaws are often successfully exploited when combined with other weaknesses.
OpenCVE Enrichment