CVE-2026-15955
moderateUnauthenticated Arbitrary File Write (Path Traversal) in IBM Db2 11.5 and 12.1
IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.5 are vulnerable to a path traversal flaw (CWE-22) in which file paths are improperly validated, allowing a remote attacker to write files to arbitrary locations on the database server. The CVSS 3.1 base score is 7.5 (AV:N/AC:L/PR:N/UI:N), meaning it is exploitable over the network with no authentication and no user interaction, and successful exploitation directly compromises integrity (an attacker could overwrite configuration files, binaries, or plant files that may facilitate further compromise such as code execution under the Db2 service account). Any organization running the affected Db2 releases is impacted, particularly those whose database listeners are reachable from untrusted networks. No public proof of concept is known, the flaw is not in the CISA KEV catalog, and there is no indication of in-the-wild exploitation at this time.
What to do: Apply IBM's fixed builds for Db2 as soon as they are released — any release above 11.5.9 or 12.1.5 respectively addresses the issue; check IBM's advisory for the exact fix pack. Until patched, restrict network access to Db2 listener ports (default 50000/TCP) at firewalls so only trusted application hosts can connect, and never expose the database listener to the public internet. Review Db2 server hosts for unexpected or recently modified files outside expected data/diagnostic directories and monitor authentication-free connection logs for anomalous activity.
| IBM Db2 | 11.5.0 through 11.5.9 |
| IBM Db2 | 12.1.0 through 12.1.5 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow a remote attacker to perform an arbitrary file write due to improper validation of file paths.
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.