Impact
IBM Db2 11.5.0 through 11.5.9 and 12.1.0 through 12.1.4 have a code execution flaw when the JDBC URL is under user control. The flaw is a classic code injection (CWE‑94) that allows a tampered connection string to cause arbitrary code to run with the privileges of the database process.
Affected Systems
Affected systems are IBM Db2 for the V11.5 release (up to 11.5.9) and the V12.1 release (up to 12.1.4). Any level of these releases that has not been patched with the special builds released by IBM is vulnerable. The special builds are version 11.5.9+ and 12.1.4+ respectively, and are named Special Build #87098 or later for V11.5.9 and Special Build #87349 or later for V12.1.4.
Risk and Exploitability
The CVSS score of 7.8 categorizes this issue as high severity, and the EPSS score is below 1 percent, indicating a low but non‑zero likelihood of exploitation. The vulnerability has not appeared in the CISA Known Exploited Vulnerabilities catalog. Attackers would need to supply a crafted JDBC URL, likely through an application that allows user input for connection strings; based on the description, the exploit requires remote interaction via the database driver.
OpenCVE Enrichment