Impact
IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.5 are vulnerable to a stack‑based buffer overflow that can be triggered when a user‑controlled or impersonated DRDA server endpoint sends malicious data. The overflow allows an attacker to execute arbitrary commands on the Db2 client with the privileges of the running process, potentially compromising confidentiality, integrity, and availability of the affected system.
Affected Systems
The affected products are IBM Db2 Enterprise editions. All.5.9 and all releases in the 12.1 series up to 12.1.5 are impacted. IBM recommends applying the security update for V11.5.9 for the 11.5 line, and for V12.1.4 V12.1.5—for the 12.1 line.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity flaw. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting limited evidence of widespread exploitation. The likely attack vector requires an attacker to communicate with or impersonate a DRDA server endpoint; thus the vulnerability can be triggered from within the network or from external hosts if the endpoint is stack buffer, and succeeds only if the endpoint processes the malicious data.
OpenCVE Enrichment