CVE-2026-15955: IBM® Data Server driver for JDBC and SQLJ could allow a remote attacker to perform an arbitrary file write due to improper validation of file paths
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow a remote attacker to perform an arbitrary file write due to improper validation of file paths.
Other sources
IBM DB2 could allow a remote attacker to perform an arbitrary file write due to improper validation of file paths.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM DB2to a version that resolves this vulnerability.Fixed in 11.5.9 - Upgrade
Upgrade
IBM DB2to a version that resolves this vulnerability.Fixed in 12.1.4 - Upgrade
Upgrade
IBM DB2to a version that resolves this vulnerability.Fixed in 12.1.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch 89304
Event History
Frequently Asked Questions
Which Db2 versions are affected?
The affected versions are IBM Db2 11.5.0 through 11.5.9 and 12.1.0 through 12.1.5.
Does exploitation require authentication or user interaction?
No. The supplied vector indicates network-based exploitation with low attack complexity, no privileges required, and no user interaction required.
What is the likely security impact?
The vulnerability allows arbitrary file writes caused by improper validation of file paths. The provided impact vector indicates integrity impact, with no stated confidentiality or availability impact.