Impact
IBM Db2 11.5.0 through 11.5.9 and 12.1.0 through 12.1.5 contain a null pointer dereference that can be triggered by a remote authenticated user. When the vulnerable code is executed, the federated server crashes, causing a restart of the database service and an interruption of all client connections. The flaw is classified as CWE‑476, representing an uninitialized reference dereference that compromises availability but not confidentiality or integrity.
Affected Systems
The affected releases are IBM Db2 11.5 and 12.1 for Linux, Unix, and Windows, including the Db2 Connect Server. Vulnerable revision levels span 11.5.0–11.5.9 and 12.1.0–12.1.5, with interim fixes shipped for 11.5.9, 12.1.4, and 12.1.5. These versions can be identified by examining the product version string.
Risk and Exploitability
The CVSS base score of 6.5 indicates medium severity. The exploitation probability is low, with an EPSS score of less than 1 %. The vulnerability is not listed in the CISA KEV catalog, and no public exploits are documented. To succeed, an attacker must authenticate to the Db2 instance over the network; the flaw is activated through specific federated server operations that lead to the null pointer dereference.
OpenCVE Enrichment