CVE-2026-9762: IBM® Data Server driver for JDBC and SQLJ is vulnerable to remote code execution when jdbc url is under user control
IBM Data Server Driver for JDBC and SQLJ is vulnerable to remote code execution when jdbc url is under user control.
Other sources
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution when jdbc url is under user control.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IBM Db2 (Data Server driver for JDBC and SQLJ)to a version that resolves this vulnerability.Fixed in 11.5.9Patch DT471454 - Upgrade
Upgrade
IBM Db2 (Data Server driver for JDBC and SQLJ)to a version that resolves this vulnerability.Fixed in 12.1.4Patch DT471454
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9762?
CVE-2026-9762 has a high severity score of 7.8.
What vulnerabilities does CVE-2026-9762 exploit?
CVE-2026-9762 exploits the remote code execution risk when the JDBC URL is under user control.
Which IBM Db2 versions are affected by CVE-2026-9762?
CVE-2026-9762 affects IBM Db2 versions 11.5.0 to 11.5.9 and 12.1.0 to 12.1.4.
How can I mitigate CVE-2026-9762?
To mitigate CVE-2026-9762, ensure that JDBC URLs are not controllable by untrusted users.
What is the potential impact of CVE-2026-9762?
The potential impact of CVE-2026-9762 includes remote code execution which can lead to unauthorized access and system compromise.