CVE-2026-87958: 
IBM Db2 脆弱性の分析と軽減

概要

CVE-2026-87958 is a denial-of-service vulnerability in IBM Db2 caused by improper privilege management (CWE-269). It affects IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.5, allowing a low-privileged authenticated user to disable specific server functionality under certain conditions. The vulnerability was published on September 10, 2026, with the GitHub Advisory Database entry added on September 11, 2026. It carries a CVSS v3.1 base score of 8.1 (High) (GitHub Advisory, IBM Support).

技術的な詳細

The root cause is classified as CWE-269 (Improper Privilege Management), where IBM Db2 fails to properly restrict or validate the actions a low-privileged user can perform against specific server functionality. The attack vector is network-based, requiring only low privileges and no user interaction, with low attack complexity. Under certain unspecified conditions, a privileged (but low-privilege) user can invoke operations that disable a specific Db2 server feature, resulting in a denial-of-service condition. No technical write-ups or proof-of-concept code have been publicly disclosed at this time (GitHub Advisory, IBM Support).

影響

Successful exploitation results in high integrity and high availability impacts, with no confidentiality impact. A low-privileged network user can disable specific functionality on an affected Db2 server, potentially disrupting database services and dependent applications. While lateral movement is not directly implied, service disruption to a critical database server could cascade to dependent business systems and workflows (GitHub Advisory).

エクスプロイト可能性

There is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation at this time. The NVD SSVC assessment confirms exploitation is currently "none" and the attack is not automatable. The EPSS score is approximately 0.21% (11th percentile), indicating a low near-term probability of exploitation. CVE-2026-87958 is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, IBM Support).

軽減策と回避策

IBM has published a support advisory for this vulnerability; organizations should consult the IBM support page for specific fix pack or interim fix details (IBM Support). As interim mitigations, restrict network access to Db2 servers to trusted hosts only, and limit administrative and privileged user accounts to the minimum necessary personnel. Monitor Db2 servers for unexpected service disruptions or unusual administrative commands. Apply IBM-provided patches or fix packs as soon as they are available for the affected 11.5.x and 12.1.x release lines.

関連情報


ソース: このレポートは AI を使用して生成されました

関連 IBM Db2 脆弱 性:

CVE 識別子

重大度

スコア

テクノロジー

コンポーネント名

CISA KEV エクスプロイト

修正あり

公開日

CVE-2026-87958HIGH8.1
  • IBM Db2 logoIBM Db2
  • cpe:2.3:a:ibm:db2
いいえいいえSep 10, 2026
CVE-2026-15955HIGH7.5
  • IBM Db2 logoIBM Db2
  • cpe:2.3:a:ibm:db2
いいえいいえSep 14, 2026
CVE-2026-86093HIGH7.5
  • IBM Db2 logoIBM Db2
  • cpe:2.3:a:ibm:db2
いいえいいえSep 10, 2026
CVE-2026-17463MEDIUM6.5
  • IBM Db2 logoIBM Db2
  • cpe:2.3:a:ibm:db2
いいえいいえSep 14, 2026
CVE-2026-16702MEDIUM6.5
  • IBM Db2 logoIBM Db2
  • cpe:2.3:a:ibm:db2
いいえいいえSep 14, 2026

無料の脆弱性評価

クラウドセキュリティポスチャーのベンチマーク

9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。

評価を依頼する

パーソナライズされたデモを見る

実際に Wiz を見てみませんか?​

"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
デビッド・エストリックCISO (最高情報責任者)
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
アダム・フレッチャーチーフ・セキュリティ・オフィサー
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"
グレッグ・ポニャトフスキ脅威および脆弱性管理責任者