Impact
IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.5 contain a privilege‑management flaw that allows an authenticated user with sufficient privileges to disable a specific server‑side function. This results in a denial of service for that functionality, impairing normal database operations without affecting data confidentiality or integrity. The weakness is identified as CWE‑269.
Affected Systems
Affected products include IBM Db2 for Enterprise Business Edition and other releases in the 11.5.0‑11.5.9 and 12.1.0‑12.1.5 ranges. The flaw is present until the provided security updates are applied to any of these versions.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity issue. EPSS is not available and the vulnerability is not listed in CISA KEV, but the flaw requires privileged access to the Db2 instance. An insider with proper credentials or a compromised account could trigger the denial of service. No public exploitation technique is disclosed, yet the design flaw presents a high risk to systems that rely on the disabled functionality.
OpenCVE Enrichment