← Back to CVE List
CVE-2026-16702NVD
Vulnerability Summary
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a remote authenticated attacker to cause a denial of service due to a null pointer dereference.
CVSS v3.1 Base Metrics — Score 6.5 (MEDIUM)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
ScopeUnchanged
ConfidentialityNone
IntegrityNone
AvailabilityHigh
Affected & Patched Versions
- IBM Db2 >= 11.5.0 and <= 11.5.9
- IBM Db2 >= 12.1.0 and <= 12.1.5
- IBM Db2 11.5.9
- IBM Db2 12.1.5