CVE-2026-87958: IBM® Db2® is vulnerable to a denial of service where a specific functionality on a Db2 server can be disabled by a privileged user under certain conditions
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to a denial of service where a specific functionality on a Db2 server can be disabled by a privileged user under certain conditions.
Other sources
IBM Db2 is vulnerable to a denial of service where a specific functionality on a Db2 server can be disabled by a privileged user under certain conditions.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Db2 11.5to a version that resolves this vulnerability.Fixed in 11.5.9Patch Security Update #89304 - Upgrade
Upgrade
IBM Db2 12.1to a version that resolves this vulnerability.Fixed in 12.1.5Patch Security Update #89304
Event History
Frequently Asked Questions
Which Db2 releases are affected?
The affected releases are IBM Db2 11.5.0 through 11.5.9 and 12.1.0 through 12.1.5.
Does exploitation require prior access?
Yes. The vulnerability requires a privileged user, so an unauthenticated external attacker is not described as able to exploit it directly.
What is the operational impact?
Under certain conditions, a privileged user can disable a specific functionality on the Db2 server, resulting in denial of service for that functionality.