Sceawere

Vulnerability Detail

CVE-2026-17463UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

IBM Db2 Resource Consumption DoS

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
3h ago
Vendor
IBM
Product
Db2
Attack Type
CWE-400 Uncontrolled Resource Consumption
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a remote authenticated attacker to cause a denial of service due to uncontrolled resource consumption.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-09-14T20:16:41.857Z",
  "pubdate": "2026-09-14T20:16:41.857Z",
  "executiveSummary": "This vulnerability is identified as a remote denial of service (DoS) condition affecting IBM Db2 11.5.0 through 11.5.9 and 12.1.0 through 12.1.5 across Linux, UNIX, and Windows platforms.\nThe root cause pertains to uncontrolled resource consumption, which can be triggered by a remote authenticated attacker.\nSuccessful exploitation allows an adversary to exhaust critical system resources, leading to service unavailability for legitimate users and applications relying on the database instance.\nThe vulnerability necessitates that the attacker possesses valid authentication credentials for the database system.\nThe risk implication is significant as it threatens the availability and operational continuity of affected Db2 database servers.\nThis flaw underscores the risk of improper resource management when handling inputs or requests from authenticated remote entities, allowing for potential service-level exhaustion.",
  "technicalDetails": "The vulnerability resides within the resource management architecture of IBM Db2, specifically affecting versions 11.5.0 through 11.5.9 and 12.1.0 through 12.1.5 on Linux, UNIX, and Windows environments.\nThe vulnerability is characterized by uncontrolled resource consumption, implying that the database engine lacks adequate safeguards, rate-limiting, or quotas when processing specific requests from authenticated sessions.\nAn authenticated attacker can exploit this by crafting and submitting specific, resource-intensive queries or requests designed to saturate the database's processing capacity, memory allocation, or connection pools.\nThe attack flow initiates with the adversary establishing a legitimate session with the Db2 instance using valid credentials. Once authenticated, the attacker issues a sequence of commands that trigger the vulnerable code path responsible for resource allocation.\nBecause the system fails to impose hard limits or implement proper error handling on these resource requests, the cumulative effect leads to resource exhaustion.\nThis behavior results in a denial of service, as the database becomes unable to allocate necessary system resources to fulfill legitimate transactions or background administrative tasks.\nThe impact of this exploit is severe, as it renders the affected Db2 instance unresponsive or causes it to crash, requiring manual intervention or service restarts to restore functionality.\nThe vulnerability does not necessarily require highly elevated privileges, provided the attacker has sufficient access to execute the payload-carrying operations within the database environment.\nThe exposure is network-based, meaning any remote interface providing access to the Db2 service is a potential vector if the attacker has gained valid authentication.\nThis issue highlights a deficiency in the internal resource governance mechanisms of the database management system, which fails to account for the impact of malicious or poorly formed requests from authenticated sources.\nThe post-exploitation result is a total degradation of service availability, preventing the database from serving the business-critical applications it supports."
}
CVE-2026-17463: IBM Db2 Resource Consumption DoS (MEDIUM Severity, CVSS: 6.5) | Sceawere