CVE-2017-1520: IBM DB2
Low severity, CVSS 3.7. EPSS: 1.3% chance of exploitation in the next 30 days.
IBM DB2 9.7, 10,1, 10.5, and 11.1 is vulnerable to an unauthorized command that allows the database to be activated when authentication type is CLIENT. IBM X-Force ID: 129830.
Affected products
- IBM DB2: version 9.7 only; version 9.7.0.1 only; version 9.7.0.2 only; version 9.7.0.3 only; version 9.7.0.4 only; version 9.7.0.5 only; …
- IBM DB2 Connect: version 9.7 only; version 9.7.0.1 only; version 9.7.0.2 only; version 9.7.0.3 only; version 9.7.0.4 only; version 9.7.0.5 only; …
Published 2017-09-12. Last modified 2026-06-17.