
Cloud Vulnerability DB
コミュニティ主導の脆弱性データベース
CVE-2026-15955 is an arbitrary file write vulnerability in IBM Db2's Data Server driver for JDBC and SQLJ, caused by improper validation of file paths. It affects IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.5 on Linux, Unix, and Windows platforms. The vulnerability was disclosed on September 14, 2026, with a patch made available the same day. It carries a CVSS v3.1 base score of 7.5 (High) (IBM Advisory).
The root cause is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory — Path Traversal). The flaw resides in the IBM Data Server driver for JDBC and SQLJ, where an "evil" (malicious or compromised) server can exploit insufficient file path validation to instruct a connected client to write arbitrary files to unintended locations on the client's file system. Exploitation requires no authentication, no user interaction, and operates over the network with low attack complexity, making it automatable (IBM Advisory). Relevant attack patterns include CAPEC-126 (Path Traversal) and CAPEC-64/76/78/79 (various encoding-based bypass techniques).
Successful exploitation allows a remote attacker to write arbitrary files to the client system's file system, resulting in a high integrity impact. While confidentiality and availability are not directly affected per the CVSS scoring, arbitrary file writes can be leveraged to overwrite configuration files, plant malicious scripts, or achieve persistent access on the client host. The attack originates from a malicious or compromised Db2 server targeting any client using the vulnerable JDBC/SQLJ driver, potentially affecting all systems that connect to untrusted Db2 server instances (IBM Advisory).
As of the disclosure date, there are no known public proof-of-concept exploits, no reported in-the-wild exploitation, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.396%, indicating a low near-term exploitation probability. NVD's SSVC assessment notes the vulnerability is automatable but exploitation has not been observed (IBM Advisory).
../../) that bypasses the driver's path validation logic.IBM has released patches addressing this vulnerability; users should upgrade the IBM Data Server driver for JDBC and SQLJ to a fixed version as detailed in the IBM advisory. Affected version ranges are 11.5.0–11.5.9 and 12.1.0–12.1.5 — users should apply the latest available fix pack. As a workaround, restrict client applications from connecting to untrusted or external Db2 server instances, and enforce network-level controls (firewalls, allowlists) to limit JDBC connections to known, trusted servers (IBM Advisory).
ソース: このレポートは AI を使用して生成されました
無料の脆弱性評価
9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。
パーソナライズされたデモを見る
"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"