PatchSiren cyber security CVE debrief
CVE-2023-33854 IBM CVE debrief
CVE-2023-33854 is a medium-severity vulnerability affecting IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data. An authenticated user could bypass client-side validation and manipulate input data using man-in-the-middle techniques. The vulnerability has a CVSS score of 5.3. IBM has provided a reference for this issue. Users should review their inventory and apply patches as available. Additional monitoring and compensating controls may be necessary.
- Vendor
- IBM
- Product
- Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-22
- Original CVE updated
- 2026-06-30
- Advisory published
- 2026-06-22
- Advisory updated
- 2026-06-30
Who should care
IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data users should review their inventory and apply patches as available. Security teams should monitor for potential exploitation and implement compensating controls as needed. Administrators should verify that client-side validation is properly configured.
Technical summary
CVE-2023-33854 affects IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, and 5.3. An authenticated user could bypass client-side validation and manipulate input data using man-in-the-middle techniques. The vulnerability has a CVSS score of 5.3 and a CVSS vector of CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N. CWE-294 is associated with this vulnerability.
Defensive priority
Apply patches as available. Monitor for potential exploitation and implement compensating controls as needed.
Recommended defensive actions
- Review inventory and apply patches as available
- Monitor for potential exploitation
- Implement compensating controls as needed
- Verify client-side validation configuration
- Consider additional security measures to prevent man-in-the-middle attacks
Evidence notes
The CVE record and NVD detail provide information on this vulnerability. IBM has provided a reference for this issue. The vulnerability has a CVSS score of 5.3 and is classified as CWE-294.
Sources and references
Verified primary and authoritative sources
-
CVE-2023-33854 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2023-33854
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2023-33854 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2023-33854
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.ibm.com/support/pages/node/7277112
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.