Impact
IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.5 contain an improper authorization flaw in a specific command that enables a non‑privileged user to bypass authentication checks and alter catalog data. The flaw exposes the database to integrity violations, which can result in unauthorized schema modifications, privilege escalation within the database, or the introduction of malicious objects. The affected command is documented by IBM as a potential vector for tampering with catalog information and can be used to subvert normal permission controls.
Affected Systems
The vulnerability affects IBM Db2 installations. For version 11.5, all releases from 11.5.0 to 11.5.9 are impacted. For version 12.1, all releases from 12.1.0 to 12.1.5 are affected. IBM has released security updates that rectify the issue; the fixes are available for 11.5.9, 12.1.4, and 12.1.5 and can be applied to any lower level of the corresponding release track.
Risk and Exploitability
The CVSS score of 4.3 suggests a moderate severity for this vulnerability. The EPSS score is not available, and it is not listed in CISA’s KEV catalog, indicating no publicly known exploits. The flaw can be exploited by any user that can execute the compromised command, likely requiring local access or a role with sufficient privileges to invoke the command. The attack vector therefore appears to be local command execution unless the command is exposed via a network service, which is not explicitly stated in the data.
OpenCVE Enrichment