← Back to CVE List
CVE-2026-15955NVD
Vulnerability Summary
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow a remote attacker to perform an arbitrary file write due to improper validation of file paths.
CVSS v3.1 Base Metrics — Score 7.5 (HIGH)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityNone
IntegrityHigh
AvailabilityNone
Affected & Patched Versions
- IBM Db2 >= 11.5.0 and <= 11.5.9
- IBM Db2 >= 12.1.0 and <= 12.1.5
- IBM Db2 11.5.9
- IBM Db2 12.1.5