Ce mail provient de l'extérieur, restons vigilants

=====================================================================

                            CERT-Renater

                Note d'Information No. 2026/VULN693
_____________________________________________________________________

DATE                : 30/06/2026

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running IBM® Db2® Server.
 
=====================================================================
https://www.ibm.com/support/pages/node/7277424
https://www.ibm.com/support/pages/security-bulletin-ibm%C2%AE-db2%C2%AE-could-disclose-sensitive-information-authenticated-user-monitoring-and-event-tables-cve-2025-36372
https://www.ibm.com/support/pages/node/7277423
_____________________________________________________________________


Security Bulletin: IBM® Db2® is vulnerable to remote code execution
due to improper pre-auth DRDA handshake handling (CVE-2026-10109)


Security Bulletin

Summary

IBM® Db2® is vulnerable to remote code execution due to improper
pre-auth DRDA handshake handling.


Vulnerability Details

CVEID:   CVE-2026-10109
DESCRIPTION:   IBM Db2 is vulnerable to remote code execution due to
                 improper pre-auth DRDA handshake handling.
CWE:   CWE-94: Improper Control of Generation of Code ('Code Injection')
CVSS Source:   IBM
CVSS Base score:   9.8
CVSS Vector:   (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)


Affected Products and Versions

Affected Product(s)	Version(s)	Applicable Editions

IBM® Db2®	11.5.0 - 11.5.9         Server
IBM® Db2®       12.1.0 - 12.1.4         Server

All platforms are affected. 


Remediation/Fixes

Customers running any vulnerable affected level of an affected Program,
V11.5, and V12.1, can download the special build containing the interim
fix for this issue from Fix Central. These special builds are available
based on the most recent level for each impacted release:V11.5.9, and
V12.1.4. They can be applied to any affected level of the appropriate
release to remediate this vulnerability.


Release           Fixed in mod pack        APAR         Download URL

V11.5             TBD                  DT471718	

Special Build #84653 or later for V11.5.9 available at this link:
https://www.ibm.com/support/pages/node/7087189

V12.1             TBD                  DT471718	

Special Build #86230 or later for V12.1.4 available at this link:
https://www.ibm.com/support/pages/node/7267513

IBM does not disclose key Db2 functionality nor replication steps for a
vulnerability to avoid providing too much information to any potential
malicious attacker. IBM does not want to enable a malicious attacker
with sufficient knowledge to craft an exploit of the vulnerability.


Workarounds and Mitigations

None


Get Notified about Future Security Bulletins

Subscribe to My Notifications to be notified of important product support
alerts like this.


References

Complete CVSS v3 Guide
On-line Calculator v3

Related Information

IBM Secure Engineering Web Portal
IBM Product Security Incident Response Blog

Published Security Vulnerabilities for DB2 for Linux, UNIX, and Windows
including Special Build information

 
Acknowledgement

Change History

23 Jun 2026: Initial Publication

*The CVSS Environment Score is customer environment specific and will
ultimately impact the Overall CVSS Score. Customers can evaluate the
impact of this vulnerability in their environments by accessing the
links in the Reference section of this Security Bulletin.


Disclaimer

According to the Forum of Incident Response and Security Teams (FIRST),
the Common Vulnerability Scoring System (CVSS) is an "industry open
standard designed to convey vulnerability severity and help to determine
urgency and priority of response." IBM PROVIDES THE CVSS SCORES
""AS IS"" WITHOUT WARRANTY OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES
OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. CUSTOMERS ARE
RESPONSIBLE FOR ASSESSING THE IMPACT OF ANY ACTUAL OR POTENTIAL SECURITY
VULNERABILITY. In addition to other efforts to address potential
vulnerabilities, IBM periodically updates the record of components
contained in our product offerings. As part of that effort, if IBM
identifies previously unidentified packages in a product/service inventory,
we address relevant vulnerabilities regardless of CVE date. Inclusion of
an older CVEID does not demonstrate that the referenced product has been
used by IBM since that date, nor that IBM was aware of a vulnerability as
of that date. We are making clients aware of relevant vulnerabilities as we
become aware of them. "Affected Products and Versions" referenced in IBM
Security Bulletins are intended to be only products and versions that are
supported by IBM and have not passed their end-of-support or warranty date.
Thus, failure to reference unsupported or extended-support products and
versions in this Security Bulletin does not constitute a determination by
IBM that they are unaffected by the vulnerability. Reference to one or more
unsupported versions in this Security Bulletin shall not create an
obligation for IBM to provide fixes for any unsupported or extended-support
products or versions.

_____________________________________________________________________


Security Bulletin: IBM® Db2® could disclose sensitive information to 
n authenticated user from the monitoring and event tables
(CVE-2025-36372)
Security Bulletin

Summary

IBM® Db2® could disclose sensitive information to an authenticated
user from the monitoring and event tables. (CVE-2025-36372)


Vulnerability Details

CVEID:   CVE-2025-36372
DESCRIPTION:   IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect
Server) could disclose sensitive information to an authenticated user
from the monitoring and event tables.

CWE:   CWE-538: Insertion of Sensitive Information into
         Externally-Accessible File or Directory
CVSS Source:   IBM
CVSS Base score:   5.5
CVSS Vector:   (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)


Affected Products and Versions
 
Affected Product(s)	Version(s)	Applicable Editions

IBM® Db2®             11.5.0 - 11.5.9    Server
IBM® Db2®             12.1.0 - 12.1.4    Server

All platforms are affected.


Remediation/Fixes

Customers running any vulnerable affected level of an affected
Program, V11.5, and V12.1, can download the special build
containing the interim fix for this issue from Fix Central. These
special builds are available based on the most recent level for
each impacted release: V11.5.9, and V12.1.4. They can be applied
to any affected level of the appropriate release to remediate
this vulnerability.

 
Release	Fixed in mod pack	APAR	Download URL

V11.5	TBD	DT452582	
Special Build #84653 or later for V11.5.9 available at this link:
https://www.ibm.com/support/pages/node/7087189

V12.1   TBD      DT452582
Special Build #86230 or later for V12.1.4 available at this link:
https://www.ibm.com/support/pages/node/7267513

 

IBM does not disclose key Db2 functionality nor replication steps for
a vulnerability to avoid providing too much information to any
potential malicious attacker. IBM does not want to enable a malicious
attacker with sufficient knowledge to craft an exploit of the
vulnerability.


Workarounds and Mitigations

Use DB2REMOTE alias. (DB2REMOTE is supported with LBAR only on 12.1
releases)

Get Notified about Future Security Bulletins

Subscribe to My Notifications to be notified of important product
support alerts like this.


References

Complete CVSS v3 Guide
On-line Calculator v3

Related Information

IBM Secure Engineering Web Portal
IBM Product Security Incident Response Blog

Published Security Vulnerabilities for DB2 for Linux, UNIX, and
Windows including Special Build information

 
Acknowledgement

Change History

25 June 2026: Updated Affected Products and Version to specify all
               platforms impact
23 June 2026: Initial Publication

*The CVSS Environment Score is customer environment specific and will
ultimately impact the Overall CVSS Score. Customers can evaluate the
impact of this vulnerability in their environments by accessing the
links in the Reference section of this Security Bulletin.


Disclaimer

According to the Forum of Incident Response and Security Teams (FIRST),
the Common Vulnerability Scoring System (CVSS) is an "industry open
standard designed to convey vulnerability severity and help to
determine urgency and priority of response." IBM PROVIDES THE CVSS
SCORES ""AS IS"" WITHOUT WARRANTY OF ANY KIND, INCLUDING THE IMPLIED
WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE.
CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT OF ANY ACTUAL OR
POTENTIAL SECURITY VULNERABILITY. In addition to other efforts to
address potential vulnerabilities, IBM periodically updates the record
of components contained in our product offerings. As part of that
effort, if IBM identifies previously unidentified packages in a
product/service inventory, we address relevant vulnerabilities
regardless of CVE date. Inclusion of an older CVEID does not demonstrate
that the referenced product has been used by IBM since that date, nor
that IBM was aware of a vulnerability as of that date. We are making
clients aware of relevant vulnerabilities as we become aware of them.
"Affected Products and Versions" referenced in IBM Security Bulletins
are intended to be only products and versions that are supported by
IBM and have not passed their end-of-support or warranty date. Thus,
failure to reference unsupported or extended-support products and
versions in this Security Bulletin does not constitute a
determination by IBM that they are unaffected by the vulnerability.
Reference to one or more unsupported versions in this Security
Bulletin shall not create an obligation for IBM to provide fixes for
any unsupported or extended-support products or versions.

_____________________________________________________________________

Security Bulletin: IBM® Db2® federated server is vulnerable to a
denial of service due to improper neutralization of special elements
in the data query logic of XMLTable-derived columns by autheticated
user (CVE-2026-11906)


Security Bulletin

Summary

IBM® Db2® federated server is vulnerable to cause a denial of service
due to improper neutralization of special elements in the data query
logic of XMLTable-derived columns by a authenticated user.

Vulnerability Details

CVEID:   CVE-2026-11906
DESCRIPTION:   IBM Db2 for Linux, UNIX and Windows (includes Db2
Connect Server) could allow an authenticated user to cause a denial
of service due to improper neutralization of special elements in the
data query logic of XMLTable-derived columns.
CWE:   CWE-1284: Improper Validation of Specified Quantity in Input
CVSS Source:   IBM
CVSS Base score:   6.5
CVSS Vector:   (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)


Affected Products and Versions
 
Affected Product(s)	Version(s)	Applicable Editions

IBM® Db2®           11.5.0 - 11.5.9      Server
IBM® Db2®	    12.1.0 - 12.1.4      Server

 

All platforms are affected. 

Remediation/Fixes

Customers running any vulnerable affected level of an affected
Program, V11.5, and V12.1, can download the special build containing
the interim fix for this issue from Fix Central. These special builds
are available based on the most recent level for each impacted
release:V11.5.9, and V12.1.4. They can be applied to any affected
level of the appropriate release to remediate this vulnerability.

 
Release	Fixed in mod pack	APAR	Download URL
V11.5	TBD	 DT466352	
Special Build #84653 or later for V11.5.9 available at this link:
https://www.ibm.com/support/pages/node/7087189

V12.1   TBD      DT466352
Special Build #86230 or later for V12.1.4 available at this link:
https://www.ibm.com/support/pages/node/7267513

IBM does not disclose key Db2 functionality nor replication steps
for a vulnerability to avoid providing too much information to any
potential malicious attacker. IBM does not want to enable a
malicious attacker with sufficient knowledge to craft an exploit
of the vulnerability.


Workarounds and Mitigations

None
Get Notified about Future Security Bulletins

Subscribe to My Notifications to be notified of important product
support alerts like this.


References

Complete CVSS v3 Guide
On-line Calculator v3

Related Information

IBM Secure Engineering Web Portal
IBM Product Security Incident Response Blog

Published Security Vulnerabilities for DB2 for Linux, UNIX, and
Windows including Special Build information

 
Acknowledgement

Change History

23 Jun 2026: Initial Publication

*The CVSS Environment Score is customer environment specific and
will ultimately impact the Overall CVSS Score. Customers can
evaluate the impact of this vulnerability in their environments
by accessing the links in the Reference section of this Security
Bulletin.

Disclaimer

According to the Forum of Incident Response and Security Teams
(FIRST), the Common Vulnerability Scoring System (CVSS) is an
"industry open standard designed to convey vulnerability severity
and help to determine urgency and priority of response."
IBM PROVIDES THE CVSS SCORES ""AS IS"" WITHOUT WARRANTY OF ANY
KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND
FITNESS FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR
ASSESSING THE IMPACT OF ANY ACTUAL OR POTENTIAL SECURITY
VULNERABILITY. In addition to other efforts to address potential
vulnerabilities, IBM periodically updates the record of components
contained in our product offerings. As part of that effort, if
IBM identifies previously unidentified packages in a
product/service inventory, we address relevant vulnerabilities
regardless of CVE date. Inclusion of an older CVEID does not
demonstrate that the referenced product has been used by IBM since
that date, nor that IBM was aware of a vulnerability as of that
date. We are making clients aware of relevant vulnerabilities as
we become aware of them. "Affected Products and Versions"
referenced in IBM Security Bulletins are intended to be only
products and versions that are supported by IBM and have not passed
their end-of-support or warranty date. Thus, failure to reference
unsupported or extended-support products and versions in this
Security Bulletin does not constitute a determination by IBM that
they are unaffected by the vulnerability. Reference to one or more
unsupported versions in this Security Bulletin shall not create an
obligation for IBM to provide fixes for any unsupported or
extended-support products or versions.


=========================================================
+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================




