[WID-SEC-2026-3308] IBM DB2: Mehrere Schwachstellen CVSS Base Score 9.8 (kritisch) CVSS Temporal Score 8.5 (hoch) Remoteangriff ja Datum 10.09.2026 Stand 11.09.2026 Mitigation ja Betroffene Systeme Betriebssystem UNIX Windows Produktbeschreibung IBM DB2 ist ein relationales Datenbanksystem (RDBS) von IBM. Produkte 10.09.2026 IBM DB2 V11.5 <APAR DT472908 IBM DB2 V12.1 <APAR DT472908 IBM DB2 V11.5 <APAR DT470425 IBM DB2 V11.5 <APAR DT473191 IBM DB2 V12.1 <APAR DT473191 IBM DB2 V11.5 <APAR DT474169 IBM DB2 V12.1 <APAR DT474169 IBM DB2 V11.5 <APAR DT474170 IBM DB2 V12.1 <APAR DT474170 IBM DB2 V11.5 <APAR DT501357 IBM DB2 V11.5 <APAR DT495924 IBM DB2 V12.1 <APAR DT495924 Angriff Angriff Ein Angreifer kann mehrere Schwachstellen in IBM DB2 ausnutzen, um beliebigen Programmcode auszuführen, beliebige Dateien zu schreiben, Daten zu manipulieren, sensible Informationen offenzulegen oder Denial-of-Service-Zustände zu verursachen. CVE Informationen Versionshistorie Feedback zum Advisory geben
Multiple critical vulnerabilities in IBM DB2 (CVSS Base Score 9.8) allow a remote attacker to execute arbitrary code, write files, manipulate data, disclose sensitive information, or cause denial-of-service. Affected versions include IBM DB2 V11.5 and V12.1 prior to the application of specific APAR fixes (e.g., DT472908, DT470425). IBM has provided mitigations; administrators must apply the relevant APARs listed for their specific DB2 version and release.