IBM Product Security Update Advisory
Overview
Security updates have been released to address vulnerabilities in IBM products. The affected products are IBM Db2 Client and IBM Db2 Server.
Affected Vulnerabilities
- CVE-2026-9762: A remote code execution vulnerability in the IBM Data Server Driver for JDBC and SQLJ.
- CVE-2026-10109: A remote code execution vulnerability in IBM Db2 caused by improper handling of the pre-authentication DRDA handshake (the procedure exchanged between the server and client when initializing a connection).
- CVE-2026-10535: A buffer overflow vulnerability in IBM Db2’s
db2flacc.
Affected Products and Versions
- IBM Db2 Client: 11.5.0 Through 11.5.9, 12.1.0 Through 12.1.4.
- IBM Db2 Server: 11.5.0 Through 11.5.9, And 12.1.0 Through 12.1.4.
Mitigation Measures
A Vulnerability Patch has been released via the latest update. You must update to the latest patched version following the instructions on the reference site.
Affected Versions
- CVE-2026-9762: For IBM Db2 Client, apply Special Build #87098 or later for V11.5.9, Or V12.1.5 Or later, or Special Build #87349 or later.
- CVE-2026-10109: IBM Db2 Server requires Special Build #84653 or later for V11.5.9, Or Special Build #86230 or later for V12.1.4.
- CVE-2026-10535: Apply Special Build #87098 or later for V11.5.9, Special Build #87349 or later, or 12.1.5 Or later to IBM Db2 Client. For IBM Db2 Server, apply Special Build #87098 or later for V11.5.9, Special Build #87349 or later, or version 12.1.5 Or later.