ZeroHour

CVE-2026-15955

moderate

Unauthenticated Arbitrary File Write (Path Traversal) in IBM Db2 11.5 and 12.1

CVSS 3.1
7.5 high
EPSS
Published
()
Modified
AI analysis

IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.5 are vulnerable to a path traversal flaw (CWE-22) in which file paths are improperly validated, allowing a remote attacker to write files to arbitrary locations on the database server. The CVSS 3.1 base score is 7.5 (AV:N/AC:L/PR:N/UI:N), meaning it is exploitable over the network with no authentication and no user interaction, and successful exploitation directly compromises integrity (an attacker could overwrite configuration files, binaries, or plant files that may facilitate further compromise such as code execution under the Db2 service account). Any organization running the affected Db2 releases is impacted, particularly those whose database listeners are reachable from untrusted networks. No public proof of concept is known, the flaw is not in the CISA KEV catalog, and there is no indication of in-the-wild exploitation at this time.

What to do: Apply IBM's fixed builds for Db2 as soon as they are released — any release above 11.5.9 or 12.1.5 respectively addresses the issue; check IBM's advisory for the exact fix pack. Until patched, restrict network access to Db2 listener ports (default 50000/TCP) at firewalls so only trusted application hosts can connect, and never expose the database listener to the public internet. Review Db2 server hosts for unexpected or recently modified files outside expected data/diagnostic directories and monitor authentication-free connection logs for anomalous activity.

Affected
IBM Db211.5.0 through 11.5.9
IBM Db212.1.0 through 12.1.5
Estimated exposure
moderateOn the order of a few thousand to low tens of thousands of internet-reachable Db2 instances, plus a substantially larger internal enterprise install base — Db2 is a widely deployed enterprise database (banks, insurers, governments), but public internet scans (e.g., Shodan) typically show only low-thousands exposure on the default Db2 listener port (50000/TCP), since most deployments sit on…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow a remote attacker to perform an arbitrary file write due to improper validation of file paths.

Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.