
Cloud Vulnerability DB
コミュニティ主導の脆弱性データベース
CVE-2026-17463 is a denial-of-service vulnerability in IBM Db2 caused by uncontrolled resource consumption (CWE-400). It affects IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.5 for Linux, UNIX, and Windows, including DB2 Connect Server. The vulnerability was published on September 14, 2026, and carries a CVSS v3.1 base score of 6.5 (Medium) (IBM Advisory).
The root cause is classified as CWE-400 (Uncontrolled Resource Consumption), where the Db2 engine fails to properly limit resource usage when processing certain requests. A remote attacker with low-level authenticated access can send crafted requests over the network that trigger excessive resource consumption, ultimately crashing or making the Db2 service unavailable. No special configuration is required beyond having valid credentials, and the attack complexity is low. Related attack patterns include XML Ping of the Death (CAPEC-147) and Regular Expression Exponential Blowup (CAPEC-492), suggesting the vulnerability may involve malformed or specially crafted input that causes resource exhaustion (IBM Advisory).
Successful exploitation results in a denial-of-service condition, causing the IBM Db2 service to become unresponsive or crash due to resource exhaustion. The impact is limited to availability — there is no confidentiality or integrity impact. Any authenticated user with low-level privileges can trigger this condition, potentially disrupting database services for all dependent applications and users (IBM Advisory).
There is no public proof-of-concept exploit available, and no evidence of in-the-wild exploitation has been observed. The NVD SSVC assessment confirms exploitation is currently "none" and the vulnerability is not automatable. The EPSS score is approximately 0.49%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog (IBM Advisory).
IBM has released a patch addressing this vulnerability, available via the IBM support page. Administrators should apply the patch immediately for affected versions (Db2 11.5.0–11.5.9 and 12.1.0–12.1.5). As interim mitigations, restrict Db2 network access to trusted users and network segments, implement connection rate limiting where available, and monitor Db2 resource consumption for anomalous patterns that may indicate exploitation attempts (IBM Advisory).
ソース: このレポートは AI を使用して生成されました
無料の脆弱性評価
9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。
パーソナライズされたデモを見る
"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"