Description
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a remote authenticated attacker to cause a denial of service due to uncontrolled resource consumption.
Published: 2026-09-14
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.5 for Linux, Unix and Windows can allow a remote authenticated attacker to trigger uncontrolled resource consumption, leading to a denial of service. The weakness is a lack of resource use control in the database server, identified as CWE-400. An attacker who can log in can cause the system to consume excessive CPU or memory, making the database unavailable to legitimate users.

Affected Systems

Affected products include IBM Db2 11.5.0 to 11.5.9 and 12.1.0 to 12.1.5, covering Linux, Unix and Windows platforms and the DB2 Connect Server component.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium severity. EPSS is not available, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires remote authentication, so only accounts with valid credentials can trigger the denial of service.

Generated by OpenCVE AI on September 15, 2026 at 13:11 UTC.

Remediation

Vendor Solution

Customers running any vulnerable affected level of an affected Program, V11.5, and V12.1, can download the security update containing the interim fix for this issue from Fix Central. These security updates are available based on the most recent level for each impacted release: V11.5.9, V12.1.4, and V12.1.5. They can be applied to any affected level of the appropriate release to remediate this vulnerability. ReleaseFixed in mod packAPARDownload URLV11.5TBD https://www.ibm.com/support/pages/node/7087189 V12.1TBD https://www.ibm.com/support/pages/node/7267513 Security Update #89304 or later for V12.1.5 available at this link: https://www.ibm.com/support/pages/node/7282633 IBM does not disclose key Db2 functionality nor replication steps for a vulnerability to avoid providing too much information to any potential malicious attacker. IBM does not want to enable a malicious attacker with sufficient knowledge to craft an exploit of the vulnerability.


OpenCVE Recommended Actions

  • Download and install the IBM security update for the affected release from Fix Central (for example, Security Update #89304 or later for V12.1.5).
  • Configure DB2 resource limits—such as maximum buffer pools and connection caps—to constrain potential excess consumption.
  • Continuously monitor system performance metrics and logs for abnormal memory or CPU usage that may indicate an attempted denial of service attack.

Generated by OpenCVE AI on September 15, 2026 at 13:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a remote authenticated attacker to cause a denial of service due to uncontrolled resource consumption.
Title IBM® Db2® could allow a remote authenticated attacker to cause a denial of service due to uncontrolled resource consumption
First Time appeared Ibm
Ibm db2
Weaknesses CWE-400
CPEs cpe:2.3:a:ibm:db2:11.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:11.5.9:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:12.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:12.1.5:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm db2
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-14T20:13:31.505Z

Reserved: 2026-07-25T19:47:21.051Z

Link: CVE-2026-17463

cve-icon Vulnrichment

Updated: 2026-09-14T20:13:20.858Z

cve-icon NVD

Status : Received

Published: 2026-09-14T20:16:41.857

Modified: 2026-09-14T21:17:03.847

Link: CVE-2026-17463

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T13:15:18Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption