Impact
IBM Db2 database engines in the 11.5 and 12.1 series contain an improper validation of file paths that permits a remote attacker to write arbitrary files to the host operating system. This path traversal flaw (CWE-22) can lead to overwrite or creation of critical files, enabling privilege escalation, tampering, or complete compromise of the server if the attacker succeeds.
Affected Systems
The affected products are IBM Db2 from the 11.5.0 through 11.5.9 releases and the 12.1.0 through 12.1.5 releases, regardless of patch level. Users of the 11.5 series should apply the security update V11.5.9, while those on the 12.1 series should use V12.1.5 to remediate the vulnerability.
Risk and Exploitability
The CVSS v3.1 score of 7.5 indicates a high severity, and the EPSS score of < 1% reflects a very low but nonzero probability of exploitation in the current data set. The flaw is not yet listed in the CISA KEV catalog. Inferred that an attacker would need remote network access to the JDBC/SQLJ interface and the ability to use the driver, making exposed database interfaces a potential entry point. The lack of a publicly documented exploit does not eliminate risk, as path traversal vulnerabilities are often combined with other weaknesses to achieve compromise.
OpenCVE Enrichment