
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-15955 is a path traversal vulnerability in IBM's Data Server Driver for JDBC and SQLJ that could allow a remote attacker to perform an arbitrary file write on a connected client due to improper validation of file paths. It affects IBM Db2 versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.5 on Linux, Unix, and Windows platforms. The vulnerability was disclosed and patched on September 14, 2026. It carries a CVSS v3.1 base score of 7.5 (High) (IBM Advisory).
The vulnerability is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory — 'Path Traversal'). The flaw resides in the IBM Data Server Driver for JDBC and SQLJ component, where an "evil" (malicious or compromised) Db2 server can exploit insufficient file path validation to write arbitrary files to locations on the connecting client system. The attack vector is network-based, requires no authentication, no user interaction, and has low attack complexity, making it exploitable by any remote party capable of acting as or controlling a Db2 server endpoint that a client connects to (IBM Advisory).
Successful exploitation allows an attacker controlling a malicious Db2 server to write arbitrary files to the filesystem of any client connecting via the vulnerable JDBC/SQLJ driver. This could result in overwriting critical system files, planting malicious executables or configuration files, or establishing persistence on client systems. While confidentiality and availability impacts are rated as none in the CVSS scoring, the high integrity impact reflects the significant risk of unauthorized file modification on client hosts (IBM Advisory).
As of the disclosure date (September 14, 2026), no public proof-of-concept exploit code or in-the-wild exploitation has been reported. The EPSS score is 0.0, indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been identified (IBM Advisory).
../../) that the vulnerable driver fails to properly validate.IBM has released patches addressing this vulnerability. Affected users should upgrade the IBM Data Server Driver for JDBC and SQLJ to a fixed version beyond 11.5.9 (for the 11.5.x line) or beyond 12.1.5 (for the 12.1.x line) as directed in the IBM advisory. As a workaround, organizations should ensure that client applications only connect to trusted, known Db2 server endpoints and restrict JDBC connection strings to approved server addresses. Network-level controls (firewalls, allowlists) can help prevent connections to unauthorized Db2 servers (IBM Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."