Description
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow a remote attacker to perform an arbitrary file write due to improper validation of file paths.
Published: 2026-09-14
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote arbitrary file write
Action: Patch Now
AI Analysis

Impact

IBM Db2 database engines in the 11.5 and 12.1 series contain an improper validation of file paths that permits a remote attacker to write arbitrary files to the host operating system. This path traversal flaw (CWE-22) can lead to overwrite or creation of critical files, enabling privilege escalation, tampering, or complete compromise of the server if the attacker succeeds.

Affected Systems

The affected products are IBM Db2 from the 11.5.0 through 11.5.9 releases and the 12.1.0 through 12.1.5 releases, regardless of patch level. Users of the 11.5 series should apply the security update V11.5.9, while those on the 12.1 series should use V12.1.5 to remediate the vulnerability.

Risk and Exploitability

The CVSS v3.1 score of 7.5 indicates a high severity, and the EPSS score of < 1% reflects a very low but nonzero probability of exploitation in the current data set. The flaw is not yet listed in the CISA KEV catalog. Inferred that an attacker would need remote network access to the JDBC/SQLJ interface and the ability to use the driver, making exposed database interfaces a potential entry point. The lack of a publicly documented exploit does not eliminate risk, as path traversal vulnerabilities are often combined with other weaknesses to achieve compromise.

Generated by OpenCVE AI on September 20, 2026 at 22:21 UTC.

Remediation

Vendor Solution

Customers running any vulnerable affected level of an affected Program, V11.5, and V12.1, can download the security update containing the interim fix for this issue from Fix Central. These security updates are available based on the most recent level for each impacted release: V11.5.9, V12.1.4, and V12.1.5. They can be applied to any affected level of the appropriate release to remediate this vulnerability. ReleaseFixed in mod packAPARDownload URLV11.5TBD https://www.ibm.com/support/pages/node/7087189 V12.1TBD https://www.ibm.com/support/pages/node/7267513 Security Update #89304 or later for V12.1.5 available at this link: https://www.ibm.com/support/pages/node/7282633 IBM does not disclose key Db2 functionality nor replication steps for a vulnerability to avoid providing too much information to any potential malicious attacker. IBM does not want to enable a malicious attacker with sufficient knowledge to craft an exploit of the vulnerability.


OpenCVE Recommended Actions

  • Download and install the IBM Fix Central update that matches the database release level—V11.5.9 for 11.5 series or V12.1.5 for 12.1 series.
  • Configure the Db2 JDBC/SQLJ driver to enforce strict path validation or restrict writable directories to a predefined trusted set, thereby mitigating the path traversal weakness.
  • Limit the exposure of the JDBC/SQLJ interface by restricting network access to trusted internal networks or implementing firewall rules to block external connections.

Generated by OpenCVE AI on September 20, 2026 at 22:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow a remote attacker to perform an arbitrary file write due to improper validation of file paths.
Title IBM® Data Server driver for JDBC and SQLJ could allow a remote attacker to perform an arbitrary file write due to improper validation of file paths
First Time appeared Ibm
Ibm db2
Weaknesses CWE-22
CPEs cpe:2.3:a:ibm:db2:11.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:11.5.9:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:12.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:12.1.5:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm db2
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-15T18:04:58.551Z

Reserved: 2026-07-16T13:16:40.449Z

Link: CVE-2026-15955

cve-icon Vulnrichment

Updated: 2026-09-15T17:51:49.174Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T20:16:39.057

Modified: 2026-09-16T19:24:58.293

Link: CVE-2026-15955

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T22:30:06Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')