Impact
A database flaw permits an authenticated Database user to issue a specially crafted request that causes the engine to write arbitrary files to the host operating system. This permits creation or overwriting of system configuration, binaries, or scripts, thereby compromising file integrity and potentially enabling code execution with the privileges of the Db2 service process. The weakness is designated as CWE‑22, representing arbitrary filesystem access. Because authentication is required, the issue is most typically exploited from within an organization or by a compromised account.
Affected Systems
IBM Db2 versions 11.5.0 through 11.5.9 and through 12 updated to the recommended security level (11.5.9 for the 11.5 series or 12.1.5 for the 12.1 series) remains vulnerable and can be remediated by installing the interim fixes available from Fix Central.
Risk and Exploitability
The CVSS base score is 4.3, indicating low to moderate severity. EPSS is not available and the flaw is not listed in CISA KEV, implying that it has not yet been actively exploited. it a local or internal threat. If an attacker can overwrite crucial system files or drop malicious binaries, they could compromise host integrity and availability.
OpenCVE Enrichment