product · May 17, 2026
IBM Releases Security Bulletin on Multiple Vulnerabilities in Db2 Affecting Big SQL on Cloud Pak for Data
Share the canonical public link.
IBM published a security bulletin on May 15, 2026, addressing multiple vulnerabilities in IBM Db2 12.1.3 and earlier versions. The issues impact IBM Db2 Big SQL on IBM Cloud Pak for Data 5.3 and earlier, including denial of service, privilege escalation, and authorization bypass with CVEs such as CVE-2024-47072 and CVE-2025-36384. Affected products include IBM Db2 Big SQL versions 7.6 through 8.3.1 on Cloud Pak for Data 4.8 to 5.3.1. IBM recommends upgrading to the latest 8.3.1 version on IBM Software Hub 5.3.1 patch 1.