← Vulnerability feed

Vulnerability record · CVE-2023-33854 · published 22 June 2026

CVE-2023-33854: Ibm db2 authentication bypass by capture-replay vulnerability

Ibm · Db2

IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, and 5.3 could allow an authenticated user to bypass client-side validation and manipulate input data using man in the middle techniques.

5.3 CVSS 3.1 Medium EPSS 0.25% · top 85.3% CWE-294 · Authentication bypass by capture-replay
5.3CVSS 3.1 base score
0.25%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
1References
26 Sep 2026Last modified by NVD

Description

IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, and 5.3 could allow an authenticated user to bypass client-side validation and manipulate input data using man in the middle techniques.

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-33854 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2012-1797Ibm db2 permissions and access controls vulnerabilityIBM DB2 9.5 uses world-writable permissions for nodes.reg, which has unspecified impact and attack vectors.EPSS 1.7%10.0CVE-2010-3731Ibm db2 memory buffer overflow vulnerabilityStack-based buffer overflow in the validateUser implementation in the com.ibm.db2.das.core.DasSysCmd function in db2dasrrm in the DB2 Administration …EPSS 9.6%10.0CVE-2010-3193Ibm db2 vulnerabilityUnspecified vulnerability in the DB2STST program in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 has unknown impact and attack vectors.EPSS 2.7%10.0CVE-2009-4335Ibm db2 vulnerabilityMultiple unspecified vulnerabilities in bundled stored procedures in the Spatial Extender component in IBM DB2 9.5 before FP5 have unknown impact and…EPSS 2.3%10.0CVE-2009-3473Ibm db2 vulnerabilityIBM DB2 9.1 before FP8 does not require the SETSESSIONUSER privilege for the SET SESSION AUTHORIZATION statement, which has unspecified impact and re…EPSS 2.0%10.0CVE-2008-6820Ibm db2 vulnerabilityThe db2fmp process in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 on Windows runs with "OS privilege," which has unknown impact and att…EPSS 1.8%10.0CVE-2008-6821Ibm db2 memory buffer overflow vulnerabilityBuffer overflow in the DAS server in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 might allow attackers to execute arbitrary code or cau…EPSS 3.7%10.0CVE-2008-4692Ibm db2 vulnerabilityThe Native Managed Provider for .NET component in IBM DB2 8 before FP17, 9.1 before FP6, and 9.5 before FP2, when a definer cannot maintain objects, …EPSS 2.1%

Source: NIST National Vulnerability Database (record CVE-2023-33854), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.