Denial of Service in IBM Db2 Federated Server
CVE-2026-10695

6.2MEDIUM

Key Information:

Vendor

IBM

Status
Vendor
CVE Published:
30 July 2026

What is CVE-2026-10695?

IBM Db2 versions 12.1.0 through 12.1.4 are exposed to a denial of service risk due to flaws in the handling of non-fenced federated queries. This vulnerability could allow an attacker to disrupt services, potentially causing significant downtime and loss of accessibility for users relying on this database system. It is crucial for organizations using these versions of Db2 to assess their exposure and implement the necessary patches provided by IBM to safeguard their systems.

Affected Version(s)

Db2 12.1.0 <= 12.1.4

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.