CVE-2015-1922

low
Published 2015-07-20 · Modified 2026-05-06
CVSS v3
CVSS v2
3.5
VIR risk
3.5

Description

The Data Movement implementation in IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and Windows allows remote authenticated users to bypass intended access restrictions and delete table rows via unspecified vectors.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: psirt@us.ibm.com — http://www-01.ibm.com/support/docview.wss?uid=swg1IT08525

vendor Authored 2026-05-27

Vendor advisory: psirt@us.ibm.com — http://www-01.ibm.com/support/docview.wss?uid=swg1IT08523

Application impact

VendorProductVersionsFixed
ibmdb29.7
ibmdb29.8
ibmdb210.1
ibmdb210.5

References

CWEs

CWE-284

Verify integrity in audit chain (admin only). AS-IS.