Description
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to a denial of service where a specific functionality on a Db2 server can be disabled by a privileged user under certain conditions.
Published: 2026-09-10
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.5 contain a privilege‑management flaw that allows an authenticated user with sufficient privileges to disable a specific server‑side function. This results in a denial of service for that functionality, impairing normal database operations without affecting data confidentiality or integrity. The weakness is identified as CWE‑269.

Affected Systems

Affected products include IBM Db2 for Enterprise Business Edition and other releases in the 11.5.0‑11.5.9 and 12.1.0‑12.1.5 ranges. The flaw is present until the provided security updates are applied to any of these versions.

Risk and Exploitability

The CVSS score of 8.1 indicates a high severity issue. EPSS is not available and the vulnerability is not listed in CISA KEV, but the flaw requires privileged access to the Db2 instance. An insider with proper credentials or a compromised account could trigger the denial of service. No public exploitation technique is disclosed, yet the design flaw presents a high risk to systems that rely on the disabled functionality.

Generated by OpenCVE AI on September 11, 2026 at 04:36 UTC.

Remediation

Vendor Solution

Customers running any vulnerable affected level of an affected Program, V11.5, and V12.1, can download the security update containing the interim fix for this issue from Fix Central. These security updates are available based on the most recent level for each impacted release: V11.5.9, V12.1.4, and V12.1.5. They can be applied to any affected level of the appropriate release to remediate this vulnerability. ReleaseFixed in mod packAPARDownload URLV11.5TBD https://www.ibm.com/support/pages/node/7087189 V12.1TBD https://www.ibm.com/support/pages/node/7267513 Security Update #89304 or later for V12.1.5 available at this link: https://www.ibm.com/support/pages/node/7282633 IBM does not disclose key Db2 functionality nor replication steps for a vulnerability to avoid providing too much information to any potential malicious attacker. IBM does not want to enable a malicious attacker with sufficient knowledge to craft an exploit of the vulnerability.


OpenCVE Recommended Actions

  • Apply IBM security update #89304 or later for DB2 12.1.5 (or the equivalent update for the V11.5.9 line) from Fix Central, following the vendor’s installation instructions.
  • Reboot or restart the affected Db2 instance to ensure the patch takes effect.
  • Verify that the previously disabled functionality is operational by performing a functional test of the service.
  • Review and restrict privileged roles and permissions to limit the ability to disable critical server functions.

Generated by OpenCVE AI on September 11, 2026 at 04:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ibm:db2:*:*:*:*:*:*:*:*

Fri, 11 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to a denial of service where a specific functionality on a Db2 server can be disabled by a privileged user under certain conditions.
Title IBM® Db2® is vulnerable to a denial of service where a specific functionality on a Db2 server can be disabled by a privileged user under certain conditions
First Time appeared Ibm
Ibm db2
Weaknesses CWE-269
CPEs cpe:2.3:a:ibm:db2:11.5.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:11.5.9:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:12.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:12.1.5:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm db2
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-09-11T14:46:10.646Z

Reserved: 2026-09-09T17:05:07.281Z

Link: CVE-2026-87958

cve-icon Vulnrichment

Updated: 2026-09-11T14:46:06.873Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-10T22:17:04.760

Modified: 2026-09-14T20:10:14.530

Link: CVE-2026-87958

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T10:15:17Z

Weaknesses
  • CWE-269

    Improper Privilege Management