{
  "document" : {
    "aggregate_severity" : {
      "text" : "hoch"
    },
    "category" : "csaf_base",
    "csaf_version" : "2.0",
    "distribution" : {
      "tlp" : {
        "label" : "WHITE",
        "url" : "https://www.first.org/tlp/"
      }
    },
    "lang" : "de-DE",
    "notes" : [ {
      "category" : "legal_disclaimer",
      "text" : "Das BSI ist als Anbieter für die eigenen, zur Nutzung bereitgestellten Inhalte nach den allgemeinen Gesetzen verantwortlich. Nutzerinnen und Nutzer sind jedoch dafür verantwortlich, die Verwendung und/oder die Umsetzung der mit den Inhalten bereitgestellten Informationen sorgfältig im Einzelfall zu prüfen."
    }, {
      "category" : "description",
      "text" : "IBM DB2 ist ein relationales Datenbanksystem (RDBS) von IBM.",
      "title" : "Produktbeschreibung"
    }, {
      "category" : "summary",
      "text" : "Ein Angreifer kann mehrere Schwachstellen in IBM DB2 ausnutzen, um beliebigen Programmcode auszuführen, um seine Privilegien zu erhöhen, um Sicherheitsvorkehrungen zu umgehen, um einen Denial of Service Angriff durchzuführen, und um Informationen offenzulegen.",
      "title" : "Angriff"
    }, {
      "category" : "general",
      "text" : "- Linux\n- Sonstiges\n- UNIX\n- Windows",
      "title" : "Betroffene Betriebssysteme"
    } ],
    "publisher" : {
      "category" : "other",
      "contact_details" : "csaf-provider@cert-bund.de",
      "name" : "Bundesamt für Sicherheit in der Informationstechnik",
      "namespace" : "https://www.bsi.bund.de"
    },
    "references" : [ {
      "category" : "self",
      "summary" : "WID-SEC-W-2026-2711 - CSAF Version",
      "url" : "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2711.json"
    }, {
      "category" : "self",
      "summary" : "WID-SEC-2026-2711 - Portal Version",
      "url" : "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2711"
    }, {
      "category" : "external",
      "summary" : "IBM Security Bulletin 7279461 vom 2026-08-09",
      "url" : "https://www.ibm.com/support/pages/node/7279461"
    }, {
      "category" : "external",
      "summary" : "IBM Security Bulletin 7282949 vom 2026-08-09",
      "url" : "https://www.ibm.com/support/pages/node/7282949"
    }, {
      "category" : "external",
      "summary" : "IBM Security Bulletin 7282951 vom 2026-08-09",
      "url" : "https://www.ibm.com/support/pages/node/7282951"
    }, {
      "category" : "external",
      "summary" : "IBM Security Bulletin 7282952 vom 2026-08-09",
      "url" : "https://www.ibm.com/support/pages/node/7282952"
    }, {
      "category" : "external",
      "summary" : "IBM Security Bulletin 7282953 vom 2026-08-09",
      "url" : "https://www.ibm.com/support/pages/node/7282953"
    }, {
      "category" : "external",
      "summary" : "IBM Security Bulletin 7284396 vom 2026-08-21",
      "url" : "https://www.ibm.com/support/pages/node/7284396"
    } ],
    "source_lang" : "en-US",
    "title" : "IBM DB2: Mehrere Schwachstellen",
    "tracking" : {
      "current_release_date" : "2026-08-20T22:00:00.000+00:00",
      "generator" : {
        "date" : "2026-08-21T09:51:11.528+00:00",
        "engine" : {
          "name" : "BSI-WID",
          "version" : "1.6.0"
        }
      },
      "id" : "WID-SEC-W-2026-2711",
      "initial_release_date" : "2026-08-09T22:00:00.000+00:00",
      "revision_history" : [ {
        "date" : "2026-08-09T22:00:00.000+00:00",
        "number" : "1",
        "summary" : "Initiale Fassung"
      }, {
        "date" : "2026-08-12T22:00:00.000+00:00",
        "number" : "2",
        "summary" : "Referenz(en) aufgenommen: EUVD-2026-57621, EUVD-2026-57620, EUVD-2026-57619, EUVD-2026-57618, EUVD-2026-57600"
      }, {
        "date" : "2026-08-20T22:00:00.000+00:00",
        "number" : "3",
        "summary" : "Neue Updates von IBM aufgenommen"
      } ],
      "status" : "final",
      "version" : "3"
    }
  },
  "product_tree" : {
    "branches" : [ {
      "branches" : [ {
        "branches" : [ {
          "category" : "product_version_range",
          "name" : "<11.5.9 Security Update #87984",
          "product" : {
            "name" : "IBM DB2 <11.5.9 Security Update #87984",
            "product_id" : "T057760"
          }
        }, {
          "category" : "product_version",
          "name" : "11.5.9 Security Update #87984",
          "product" : {
            "name" : "IBM DB2 11.5.9 Security Update #87984",
            "product_id" : "T057760-fixed",
            "product_identification_helper" : {
              "cpe" : "cpe:/a:ibm:db2:11.5.9_security_update_87984"
            }
          }
        }, {
          "category" : "product_version_range",
          "name" : "<12.1.4 Security Update #86025",
          "product" : {
            "name" : "IBM DB2 <12.1.4 Security Update #86025",
            "product_id" : "T057761"
          }
        }, {
          "category" : "product_version",
          "name" : "12.1.4 Security Update #86025",
          "product" : {
            "name" : "IBM DB2 12.1.4 Security Update #86025",
            "product_id" : "T057761-fixed",
            "product_identification_helper" : {
              "cpe" : "cpe:/a:ibm:db2:12.1.4_security_update_86025"
            }
          }
        }, {
          "category" : "product_version_range",
          "name" : "<12.1.5 Security Update #88454",
          "product" : {
            "name" : "IBM DB2 <12.1.5 Security Update #88454",
            "product_id" : "T057763"
          }
        }, {
          "category" : "product_version",
          "name" : "12.1.5 Security Update #88454",
          "product" : {
            "name" : "IBM DB2 12.1.5 Security Update #88454",
            "product_id" : "T057763-fixed",
            "product_identification_helper" : {
              "cpe" : "cpe:/a:ibm:db2:12.1.5_security_update_88454"
            }
          }
        }, {
          "category" : "product_version_range",
          "name" : "<12.1.4 Security Update #87349",
          "product" : {
            "name" : "IBM DB2 <12.1.4 Security Update #87349",
            "product_id" : "T057764"
          }
        }, {
          "category" : "product_version",
          "name" : "12.1.4 Security Update #87349",
          "product" : {
            "name" : "IBM DB2 12.1.4 Security Update #87349",
            "product_id" : "T057764-fixed",
            "product_identification_helper" : {
              "cpe" : "cpe:/a:ibm:db2:12.1.4_security_update_87349"
            }
          }
        } ],
        "category" : "product_name",
        "name" : "DB2"
      }, {
        "branches" : [ {
          "category" : "product_version",
          "name" : "9.2.0-9.2.44.1",
          "product" : {
            "name" : "IBM License Metric Tool 9.2.0-9.2.44.1",
            "product_id" : "T058460",
            "product_identification_helper" : {
              "cpe" : "cpe:/a:ibm:license_metric_tool:9.2.0_-_9.2.44.1"
            }
          }
        } ],
        "category" : "product_name",
        "name" : "License Metric Tool"
      } ],
      "category" : "vendor",
      "name" : "IBM"
    } ]
  },
  "vulnerabilities" : [ {
    "cve" : "CVE-2026-10534",
    "product_status" : {
      "known_affected" : [ "T058460", "T057760", "T057761", "T057763", "T057764" ]
    },
    "release_date" : "2026-08-09T22:00:00.000+00:00",
    "title" : "CVE-2026-10534"
  }, {
    "cve" : "CVE-2026-10543",
    "product_status" : {
      "known_affected" : [ "T058460", "T057760", "T057761", "T057763", "T057764" ]
    },
    "release_date" : "2026-08-09T22:00:00.000+00:00",
    "title" : "CVE-2026-10543"
  }, {
    "cve" : "CVE-2026-16480",
    "product_status" : {
      "known_affected" : [ "T058460", "T057760", "T057761", "T057763", "T057764" ]
    },
    "release_date" : "2026-08-09T22:00:00.000+00:00",
    "title" : "CVE-2026-16480"
  }, {
    "cve" : "CVE-2026-18096",
    "product_status" : {
      "known_affected" : [ "T058460", "T057760", "T057761", "T057763", "T057764" ]
    },
    "release_date" : "2026-08-09T22:00:00.000+00:00",
    "title" : "CVE-2026-18096"
  }, {
    "cve" : "CVE-2026-18097",
    "product_status" : {
      "known_affected" : [ "T058460", "T057760", "T057761", "T057763", "T057764" ]
    },
    "release_date" : "2026-08-09T22:00:00.000+00:00",
    "title" : "CVE-2026-18097"
  } ]
}