CVE-2026-16702: IBM® Db2® federated server could allow a remote authenticated attacker to cause a denial of service due to a null pointer dereference
DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a remote authenticated attacker to cause a denial of service due to a null pointer dereference.
Other sources
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a remote authenticated attacker to cause a denial of service due to a null pointer dereference.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch 89304 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.5.9 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 12.1.4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 12.1.5
Event History
Frequently Asked Questions
Which deployments are affected?
The issue affects Db2 for Linux, UNIX, and Windows, including Db2 Connect Server, in versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.5. The affected functionality is identified as the Db2 federated server.
What access does an attacker need?
An attacker must be remotely reachable and authenticated. No user interaction is required for exploitation.
What is the expected impact?
Successful exploitation can cause a denial of service through a null pointer dereference. The provided severity vector indicates availability impact without confidentiality or integrity impact.