Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-15955
IBM Db2 vulnerability analysis and mitigation

Overview

CVE-2026-15955 is a path traversal vulnerability in IBM's Data Server Driver for JDBC and SQLJ that could allow a remote attacker to perform an arbitrary file write on a connected client due to improper validation of file paths. It affects IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.5 on Linux, Unix, and Windows platforms. The vulnerability was disclosed and patched on September 14, 2026. It carries a CVSS v3.1 base score of 7.5 (High) (IBM Advisory).

Technical details

The vulnerability is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory — 'Path Traversal'). The flaw resides in the IBM Data Server Driver for JDBC and SQLJ component, where an "evil" (malicious or compromised) Db2 server can exploit insufficient file path validation to write arbitrary files to locations on the connecting client system. The attack vector is network-based, requires no authentication, no user interaction, and has low attack complexity, making it exploitable by any remote party capable of acting as or controlling a Db2 server endpoint that a client connects to (IBM Advisory).

Impact

Successful exploitation allows an attacker controlling a malicious Db2 server to write arbitrary files to the filesystem of any client connecting via the vulnerable JDBC/SQLJ driver. This could result in overwriting critical system files, planting malicious executables or configuration files, or establishing persistence on client systems. While confidentiality and availability impacts are rated as none in the CVSS scoring, the high integrity impact reflects the significant risk of unauthorized file modification on client hosts (IBM Advisory).

Exploitability

As of the disclosure date (September 14, 2026), no public proof-of-concept exploit code or in-the-wild exploitation has been reported. The EPSS score is 0.0, indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been identified (IBM Advisory).

Exploitation steps

  1. Set up a malicious Db2 server: The attacker configures a rogue IBM Db2-compatible server endpoint designed to respond to JDBC/SQLJ client connections.
  2. Lure or redirect a client: The attacker tricks a target application or user into connecting their IBM Data Server Driver for JDBC and SQLJ to the malicious server — for example, via a manipulated JDBC connection string, DNS poisoning, or a man-in-the-middle attack.
  3. Exploit path traversal: During the connection or data exchange, the malicious server sends a crafted response containing a file path with traversal sequences (e.g., ../../) that the vulnerable driver fails to properly validate.
  4. Write arbitrary file: The driver writes attacker-controlled content to an arbitrary location on the client's filesystem, potentially overwriting system files, dropping a web shell, or planting a malicious binary for later execution (IBM Advisory).

Indicators of compromise

  • File System: Unexpected or newly created files in directories outside the expected JDBC driver working directory; files with path traversal artifacts in their names or metadata; modified system or configuration files on Db2 client hosts.
  • Network: Outbound JDBC/SQLJ connections from client applications to unfamiliar or unauthorized Db2 server IP addresses or hostnames; unusual DNS resolution for Db2 server endpoints.
  • Logs: Application or driver logs showing connections to unexpected Db2 server endpoints; file I/O errors or warnings in JDBC driver logs referencing unusual file paths; OS-level audit logs recording file creation or modification events by the Java process running the JDBC driver in unexpected directories.

Mitigation and workarounds

IBM has released patches addressing this vulnerability. Affected users should upgrade the IBM Data Server Driver for JDBC and SQLJ to a fixed version beyond 11.5.9 (for the 11.5.x line) or beyond 12.1.5 (for the 12.1.x line) as directed in the IBM advisory. As a workaround, organizations should ensure that client applications only connect to trusted, known Db2 server endpoints and restrict JDBC connection strings to approved server addresses. Network-level controls (firewalls, allowlists) can help prevent connections to unauthorized Db2 servers (IBM Advisory).

Additional resources


SourceThis report was generated using AI

Related IBM Db2 vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-87958HIGH8.1
  • IBM Db2 logoIBM Db2
  • cpe:2.3:a:ibm:db2
NoNoSep 10, 2026
CVE-2026-15955HIGH7.5
  • IBM Db2 logoIBM Db2
  • cpe:2.3:a:ibm:db2
NoNoSep 14, 2026
CVE-2026-86093HIGH7.5
  • IBM Db2 logoIBM Db2
  • cpe:2.3:a:ibm:db2
NoNoSep 10, 2026
CVE-2026-17463MEDIUM6.5
  • IBM Db2 logoIBM Db2
  • cpe:2.3:a:ibm:db2
NoNoSep 14, 2026
CVE-2026-16702MEDIUM6.5
  • IBM Db2 logoIBM Db2
  • cpe:2.3:a:ibm:db2
NoNoSep 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management